This report does not surprise me at all, nor do the comments above.
Being an IT integrator focused on Security, we attend about half a dozen sites a month that have not implemented an acceptable level of security and have been exposed to some type of attack/infection etc.
With regard to the comments above, it doesn't cost a fortune to get to an acceptable level, the threat landscape is a moving target that needs regular review.
There are NO guarantees. Period. You can't stop your house from being burgled, but you shouldn't leave it exposed either.
Our industry is FULL of people who don't know what they are talking about, but hopefully after 30 years I have at least got a grasp of it, but there's still a lot to learn.