The interesting thing about Snowden to me after 10 years is how few times I see the public think about how low-level staff with hardware-level access can bypass all command and control decisions. He was a contractor who just wholesale scooped data off the servers. Nearly 10 years later... Jack Teixeira leaks documents because he has server access to documents outside his immediate need too.
I think a lot of organizations really don't see how vulnerable they are to deliberate attacks and theft - if the NSA can't protect their data 10 years ago, do you really think your mobile phone network provider or these VPN companies are not subject to internal staff selling off data, etc?