Earlier quoted context omitted.
The fine is small since they completely complied with all inquiries and took proper steps to inform users and improve security. Thus do what the actual goals is. Making money is no a goal of GDPR, but ensuring data safety.
Fines need to be extremely punitive to make the risk-reward analysis favour fixing security _before_ the company gets caught.
True, if there is no punishment and a threat is teethless nobody acts on it (that's why the big GDPR outcry also came only this year after the two year introductory phase)
However if you have too high fines what happens s that companies try everything to hide the fault and lie to avoid the fines. Here a company complied to all things, improved security (which according to the data privacy agency let to six digit costs (while a question is how you measure this) - see other comments) and therefore got a low punishment.
The punishment also has another effect: It makes it clear that fines are being collected. If it were higher the Knuddels company would go to court and we'd have an example case only in two or more years.
The goal is to improve data safety. That goal was achieved.