presence of firewall would mean that somebody took some care about the web interface security. Once at it, they could go as far as to even patch the Apache ... The described situation at Sony seems that nobody took any care. Why would the company need a good sysadmin when it has an army of lawyers and money for it :)
"Sony said it has added automated software monitoring and enhanced data security and encryption to its systems in the wake of the recent security breaches."
sounds like they have thrown a substantial amount of money (instead of skills) into the problem.