In which case systems need to be designed so that a 'stupid user' cannot bring them down. Not everyone is a computer geek and understand how these things work.
Oh I agree, the blame lies on the IT staff (speaking from someone within the field), the legacy systems should have been air gapped, but unfortunately most ransom ware etc is targeted at the front end user.
This is a strain on the linux worm that was produced by NSA and was leaked in the Vault7 stuff, the problem is that it was the IT bods who where shouting how everyone should take note, but was met with the usual "I've done nothing wrong, so I have nothing to fear" response.