@hrbrmstr i think its safe to say that its not "victim blaming" if
the person in charge of securitys JOB is to have a threat model
failure to predict what would otherwise be obvious stuff means they suck at their job
if youre the head of security of a major healthcare org and you suck at your job, thats the boards fault for hiring someone who doesnt know what theyre doing
it shows that leadership is being lazy or ignorant.
THATS what should be punished. the laziness/ignorance