Virgin Media is profit-first, above all else. It's an error to assume that the part of the company that builds out infrastructure is in any way joined up with the part of the company that keeps customers secure (if indeed, they even have people responsible for that, which they apparently don't).
This is why things like GDPR end up being foisted on us. Corporations have proven themselves capable of simply ignoring legislation designed to protect their customers, and simply paying a fine later. They'll secure when it's convenient to them, and not a minute earlier.