Re: "sophisticated"
We didn't bother with security because it's boring and security people just cost money and point out problems.
If we get rid of security people we save money and don't have any problems to fix. Double win.
Now we've been hacked we need to make a show of improving security, mostly by saying in press releases how "customers data is our #1 priority". We'll get in some consultancy for a few days to cover the press releases and ICO prying, and we'll let the IT geeks run a few updates as long as it doesn't break anything. But no budget increases. In fact cuts to pay for the two days of security consultancy and the shredder to get rid of their report.
Than back to business as usual. After all lightning never hits the same spot twice does it?