Not really. If they are dedicating resources to this instead of improving their across the board woeful security practices then it is relevant.

And it does beg the question if they can't manage their own infrastructure why would anyone be silly enough to let them manage theirs ?

