I think that the third parties who have been granted access to the civil registry should be audited on a regular basis for the “best practices” of the day. Similar to the participants of the payment systems like VISA or MC that are regularly audited for PCI standards.
Or simply make people who choose insecure passwords criminally responsible for the fallout.
A least privilege access redesign seems reasonable too. And abuse monitoring; the leak went on for 21 days undetected.