Safe harbor is not unconditional. The protection is for organizations that were making a reasonable effort, not for organizations with no controls at all. The eligibility threshold is built around CIS ...
There is an old (very old) adage that says: if you connect it to the internet, it can be hacked. A more accurate one would be; if you can interact with it in any way, it can be hacked. We have seen ...