Earlier quoted context omitted.
Maybe, but running unauthenticated databases on the public internet is negligent at best.
No. It could be simple ignorance. Or an accident. In your world, what is it at worst? Criminal? Capital?
However, if it's a mid-sized business handling important information, like payment information, then I do think there ought to be a standard of dutiful behavior, because otherwise who pays for the externalities?