The article talks about what ISPs must do during the incident; however, it does not talk about why it happened in the first place.
ISPs provide ultra-cheap locked-down ONUs with default credentials. They always come with poor security and are never patched for vulnerabilities.
Plus, it sucks that these ISPs do not even allow enthusiasts to use their own device easily.
Most importantly, these ISPs don't even do source address validation, which means anyone can spoof themselves to be any IP.