Of course, it would have reduced damaged, such as pointing out that unhashed or unsalted MD5 passwords in a database is... what we've stopped doing 20 years ago for good reasons? :)
But well, if you're a big hosting provider tailoring to white supremacist content, you usually don't need so much security, since apart from anonymous-adjacent antifascists pretty much everyone is licking your boots, including law enforcement. The biggest neonazi forums have been around for decades, and their biggest proponents are well hidden behind the walls of our police stations, banks and parliaments.
Love the reference to Woody Guthrie, too https://en.wikipedia.org/wiki/This_machine_kills_fascists
That's the opportunity cost of defending. It's like walking through treacle at times, but you have to visualize the worst case scenario in your head and act as if you're gonna get breached. You need to essentially enact the situation in your head so that it gives you the momentum you need to keep defending.