Every company, car or otherwise, has security grossly inadequate for the current and especially the near future threat landscape. Everybody knows everything is easily hacked and companies people tout as exemplars like Apple and Microsoft just keep piling on the abject failures to prove the common wisdom true like it is going out of style. Decades of claimed success followed shortly after by failure after failure should really pound in the lesson: "Fool me once, shame on you. Fool me ten thousand times, shame on me."
You need systems secure against teams commercially motivated attackers with 10 M$+ budgets and tens of full-time professionals working for years. Nobody in commercial IT would even dare to claim they could stop such attacks even though they are regular occurrences these days. If they do not even dare to say they can do it, why on Earth would anybody believe those vendors have, what, accidentally made things better than they think?
Ranking companies by security is like ranking the relative resistance of individual sheets of toilet paper to bullets. Sure, maybe the single ply toilet paper is not as good as the two ply, but neither of them provide objectively useful degrees of protection. And that is just talking about the bare minimum to protect against current threats.
If you can hack every Honda at rush hour to turn off the brakes, slam the accelerator, and drive slightly into oncoming traffic how many people do you think would die in the next minute before anything can be done or people informed to stop driving their cars? 1K? 10K? 100K? 1M? Does Honda survive killing more people than died in most wars? If a criminal organization demonstrates they can and will do it, how much would Honda pay in extortion to avoid being put out of existence and their executives jailed? How much security is adequate to avoid the deaths of thousands to millions? Certainly orders of magnitude more than the 10 M$ attacks that steam roll the "best commercial IT security" available today. Any reasonable number is vastly in excess of what these companies can secure today.
20 years ago, the hackers were 18 year olds demanding 300 dollars from grandmas. 10 years ago, the hackers were 28 year olds founding businesses demanding 10 thousand dollars from small businesses. Now they are 38 year olds managing teams demanding millions from billion dollar companies. Soon we will see them demanding billions if the trends continue for 5-10 more years. The software security doomsayers were right, just early. Even Mark Zuckerberg took a decade with huge piles of VC funds to get to a multi-billion dollar valuation; you have to forgive the hacking teenagers who had to bootstrap their criminal enterprises for taking so long.