If MNHQ had had their heads screwed on and took their security obligations seriously, they would have paid for professional cyber security advice, to protect the data they control from hackers, including taking action against staff with malicious intent. You can't just 'wing it' and hope for the best!
If they go with a US behemoth like Amazon, they need to be sure the server is hosted in an EU country to be GDPR compliant. That may seem elementary, but it's surprising how the most basic of cyber security and privacy principles trip people up and they forget to ask the right questions, until it's too late! They need all their internal processes to be ISO27001 compliant, and not 'sub-contract' that obligation to a web service provider.
It has taken Covid19 to expose serious chinks in their armour, they should have been better prepared. The greatest harm to a business is loss to reputation, which is often unrecoverable.