I'm more interested at this point in figuring out what this means for the future. Do we live in a world now where state-actors will target specific companies and basically try to rip them to shreds and extort them? Now I'm supposed to personally defend my company and my network against state-sponsored targeted persistent threats?
It should be possible to lock down individual machines which aren't ever supposed to be networked. That's hard enough. I'm personally of the belief that any networked device is ultimately hack-able up to the physical constraints of the network. It's all about how much it will cost an attacker to gain access, and how much they can steal once they get it.
If governments start routinely sponsoring these attacks, I'm very concerned the cost-levels we impose today are 5 - 6 orders of magnitude too low, and the network bandwidth 5 - 6 orders of magnitude too high, to deter these types of attack.