I learned a long time ago that the default assumption for non-tech-first companies should be deep, deep incompetence, below the level of an undergrad with a decent CS degree, when it comes to basic security practice. Even having your system be Incredibly Important isn't enough to force basic competence: there were plenty of government and bank systems through the 2000s that were apparently designed and maintained by…
"non-tech-first companies" Is an ISP not tech first? Bell labs is an off shoot of a phone company, early computing was based on the efforts of phone companies. Phone companies, which ISPs are the modern variant are the original tech companies. Edit to add: Virgin maintains a fibre optic network so we aren't just talking about a sales front end to someone else's network.
This is why things like GDPR end up being foisted on us. Corporations have proven themselves capable of simply ignoring legislation designed to protect their customers, and simply paying a fine later. They'll secure when it's convenient to them, and not a minute earlier.