I say poor way to look at it because it gives similar reasoning to small businesses and non profits
I say poor way to look at it because it gives similar reasoning to small businesses and non profits not taking their InfoSec seriously because they're not worth going for, which is tge exact reason that makes it worth going for. Easy food. Most malicious attackers don't care where the money comes from, just that they get it. Why chase a $100B company you'll probably never get any inside info in when you can get a few 5-7 figures companies and get you rolling for long term funding to keep getting those same small fishies? Sure, it's not a "big score", but it all adds up.
