I'm not sure what technology industry you are in, but in the one I'm in software engineers are fooled by phishing attacks extremely consistently, people routinely expose critical systems and devices to the internet, developers often expose databases with insecure defaults to the internet over well-known ports, customer data gets stolen on a regular basis, etc., etc., etc. Regardless of how one feels about the government, I don't think the average technology company does any better when it comes to securing its own infrastructure.