Earlier quoted context omitted.
A web app was compromised through SQL injection, then lateral movement was used to get to the mailserver (which may or may not have been on the same box). If their aim was the highest level of security, then such lateral movement should not have been possible.
> If their aim was the highest level of security Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong. Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else. If their source code was stolen, the…
I wouldn't use a dentist with bad teeth. I wouldn't get my hair cut by somebody with a bad hair cut. I wouldn't let my garden be tended by someone with an ugly yard.
You're completely right, they don't have to have absolutely perfect security, but it's a business card in the same way that getting all your data hacked and posted to the Pirate Bay is an anti-business card.