Overlapping issues at play here
After reading this article, I have the feeling that there are several issues that are at the root of this problem.
First, there's the fact that ServiceNow has had to amend its platform to bolster security. That tells me that their handling of security wasn't properly thought through in the first place.
Then there's the fact that, despite having amended the platform, customers are still getting it wrong, which points to a possible lack of clarification in the documentation. It's difficul to write good security documentation when you're tacking on a new process that changes everything.
Finally, there's the fact that customers don't have time for security, they just want things to work. Maybe some customers gave it a try and found that their new configuration broke their processes and, instead of correcting the processes, they reverted to the old, insecure configuration. Maybe some customers just didn't understand the problem and left everything as is because they had enough trouble getting it working in the first place.
In any case, this whole affair demonstrates just how important it is to establish proper security from the start. Making such corrections after the fact is always a problem in itself.