Agreed. Some orgs are better than others at practicing good security hygiene.

The better ones have awareness of their network and have systems monitoring their networks, etc. There are afterall the equivalents of Qualys in the IA world.

