If Google can fall victim to an ICS attack, anyone can.
Did Google write this software? If not, it's kind of like writing "Google locks vulnerable to lock picks". Well yeah, just like every other pin tumbler lock ever made.
I think the point was that if any company should have awareness of what internal tools are pointing web servers at the outside world, should be capable of auditing its own security, should easily understand what that software is doing and how it should be secured, it should be Google, a company whose primary output is web software.
No they didn't. This is actually run by a third party as Google does not own these offices. FWIW Google has a pretty decent security team, although for some reason most of them are arrogant assholes (e.g. Tavis Ormandy)
Did Google write this software? If not, it's kind of like writing "Google locks vulnerable to lock picks". Well yeah, just like every other pin tumbler lock ever made.