Generally I'd agree except for two points.
1) From what I've seen, at least on the military side, the "training people" concept was actually one of the things they've sacrificed over the past decade or so (and even in the late 1990s) -- it's still obviously done in areas where it's "inherently military or governmental" like flying fighter aircraft, but contractorization has caused the government sphere to revert to more like the commercial world -- fewer people genuinely trained to a good standard from scratch. There's both a higher bar for entry, and a lower output quality.
It might be totally different in the civilian government world stateside, but somehow I doubt it.
The only government jobs which seem to successfully recruit and build skills are government offense jobs (NSA TAO, etc.). Judging by results, on the defense side, they're doing a horrible job of recruiting and using their recruits. From that I've seen of DHS and USCYBERCOM recruiting, it's no better than the commercial world. USCYBERCOM has the benefit of the entire incoming recruit stream of the military, but they've been fairly slow even to train tech/operator level people. That the military is taking that big a role on civilian defense is a sign that DHS/etc. haven't been very successful recruiting for defense.
2) "10 years ahead of private industry" -- not really, since there's essentially a fusion of the contractor space and government. If BAH were somehow vastly more effective than commercial companies, you'd expect them to go into profitable civilian work as well, but only an abject fucking moron would hire any of the defense contractors to do anything if not required to do so by the government (government work is NOT more profitable than the best commercial work, so a competent firm would be motivated to do both). The flow goes the other way; Palantir came from the commercial world back into the government world.
Underestimating one's adversary is always a bad idea, but overestimating them is also bad (if it causes you to give up). The fundamental issue is that a large number of people don't consider USG to be their adversary, and for the most part, it isn't -- congress has abjectly failed in its oversight role, and programs have gotten far too big (in budget and scope), infringing rights (mainly theoretically, still), but a lot of people believe there's both a proper defense role for the military, and that the threats are growing/changing and require IT security.
Remember, even if you love the USG/NSA mission, they have three big handicaps: secrecy, bureaucracy, and security (i.e. being US citizen only). Think about how fucked up a tech company would be if it got to the scale of Microsoft or Google but without being able to hire non-citizens, have people enter/leave freely, hire anyone with at all a shady background, interact much with the outside world, etc. Then add politicians and political appointees, plus 1-2 year stint military, into key roles. From everything I've heard, NSA dealt with that in ancient times (pre-1990s) pretty well, by having career NSA people run things for other career NSA people, but they ended up in a rat-hole of focusing on the PSTN/leased line and under-exploiting the Internet. There were three main eras: the real cold war where everything was mission-driven by the soviets, the "lost years" between the end of the cold war and 9/11, and the new agency post-9/11 focused on commercial systems and "terrorists". CIA had the same challenge...a spy v spy mission, then counterdrug/etc. insanity, and then became basically global assassins and jailers.