There is always a way. People will always find an exploit etc. Sometimes it could take months.
Technically yes; in practice, no, there isn't really "always a way"; if there was, all major websites would be frequently down from attacks.
99% of hacking uses known exploits, which can be prevented relatively "trivially" by any admin with half a brain by simply keeping all systems up to date, and following bulletins of the latest exploits.
90% of hacking is automated. All sites are continually under attack. If your software is up to date, and you don't have any other obvious stupid holes, you can sleep easy at night, it won't take "months", it will take "indefinitely", because an automated hack targeting a patched exploit can go on for years with no problem - it's not a matter of time, it's a matter of "either you're vulnerable or you're not", i.e. "either the attempt will succeed the very first time, or it will never succeed" (the only type of target hacking attempt that might really go on "months" would be things like brute-force password checks, which can also be easily circumvented by even a half-competent IT admin: Use strong passwords ALWAYS, and turn off password login on services like SSH). It is naive IT admins who see these attempts in their logs and go "oh n0e5 we're under attack!" ... um, nope, it's just some automated script looking for known exploits that you should've patched.
0.1% of hackers actually try find new exploits, and it's rare to see these be used. Also, if you're worth your salt as an IT admin, newly published exploits won't cause major problems either, because you just keep on top of the patches and go on your way. If the site gets hacked, restore from backup, and continue on your way.
The only hacking that is truly difficult to prevent is those that use unpublished new exploits. That is such a tiny minority, and the people doing that are usually farming their skills out to criminal enterprises. I doubt they care about Mail and Guardian specifically.