broke into US-based water facilities by using default passwords for internet-accessible PLCs
At which point the board of the company should personally be on the hook for failing to perform any form of network security. Not that they would personally do it, but they clearly were negligent in their duty to employ competent staff, and to have any sort of checking process at all.
This is not "victim blaming" but holding those to account who should be protecting strategic infrastructure.