Swing and a miss. There's plenty of security consultants around who can help Sega set up the testing and reporting to identify and address vulnerabilities and manage future ones as they change systems. You don't need haxors to pwn ur stuf and sho u how.
Even if they do a good job (and don't tell all their friends what you decided NOT to fix right away), that leaves you with nothing but a system security snapshot (which is step 1 in setting up security management) and nothing for ongoing monitoring, reporting and management. That's all about setting the business up for the work of security management and has nothing to do with how good a haxor you hire.
Sounds like Sega's executives have been watching too much CSI - Internet.