Earlier quoted context omitted.
Which they did. The problem of hardening your build infrastructure against someone who has admin access for months is... non-trivial. This boils down to the question of should average companies be including the Russian intelligence services in their threat model? To paraphrase James Mickens great USENIX paper, if your threat model includes the SVR, you're going to be SVR'd upon.
First, you do not need to be the Russian intelligence services to pull off this attack. Given prevailing trends in the vulnerabilities market this sort of attack would cost at most $1M to pull of which puts it within the capabilities of maybe ~50,000,000 individuals worldwide let alone organizations. If the SVR is anything like the CIA they are probably running at least 1,000 programs of similar scale simultaneously,…
I have always argued that doing what I call "defense by presumed motive". The logic would have been "ok, UNC2452 wants to access DHS hacker's email. I'll go after SolarWinds". Better spend your energy on basic security principles.