If someone puts a low rank admin assistant in charge then the boss needs prosecuting. It would be the public sector version of getting the boss's nephew to do it.
But that's not what happened. It wasn't left unpatched because of incompetence of the developers. It's because it cannot be upgraded to a secure version of the software and to replace the entire system would cost a lot of money. Money that the Tory govt didnt want to spend. There are ongoing efforts to reduce reliance on this legacy tech but it's not an overnight solution.