Earlier quoted context omitted.
> It was true at Google. Yes, because Google is not your average company. It takes security extremely seriously... in fact it's about as awful of an example as you can give for a blanket statement you made about "most companies".
I'm not sure if Google even has an internal red team that performs breaches, last time I talked with someone there at a conference they didn't (that was 2016). So I am not sure Google has metrics on how easy it is to gain access by an adversary.
2012: Google staffs up ‘Red Team’
And this was literally just a Google away: https://nakedsecurity.sophos.com/2012/08/24/google-red-team-...