Earlier quoted context omitted.
We don't know if the security of the mailserver was at stake here. A web app was compromised through SQL injection, then lateral movement was used to get to the mailserver (which may or may not have been on the same box). The rootkit.com mail server has nothing to do with HBGary AFAIK. To put it in perspective, HBGary's (not HBGary Federal) technology is a thing called Digital DNA that cuts down the amount of time it…
A web app was compromised through SQL injection, then lateral movement was used to get to the mailserver (which may or may not have been on the same box). If their aim was the highest level of security, then such lateral movement should not have been possible.
Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong.
Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else.
If their source code was stolen, then yes you could say that the level of protection was inappropriate because if the source code is the highest value asset they have, it probably shouldn't be accessible from the Internet.
That an Internet-facing web app was broken into and an email server for receiving and sending email to and from the Internet means that they have to be connected to the Internet to work. If these systems contained information assets that were sufficiently sensitive to the point of considering post-compromise lateral movement then they probably shouldn't be connected to the Internet.