What it sounds like from the article isn't that he destroyed $200,000 worth of property; it's that $200k is what it cost Facebook to fix a security hole he discovered. Meaning it was money they needed to spend on security before someone with truly malicious intentions found it. Does Facebook seriously think that sending kids to jail is a viable substitute for building good security into their product, or that it will deter future attempts and mean they won't have to spend another $200k next time? More likely, next time they won't know about it, or it will come from a country where they have no power to find the responsible party. They should be on their knees thanking this kid; just another reason to loathe FB, I guess.
In general, the time to fix an identified security hole is dwarfed by the time to investigate a breech.
You have to identify the actions taken by the attacker and correlate events between systems to understand the extent of stolen, destroyed, or modified information, and to ensure that no additional backdoors are left behind.
If there is an indication of malicious intent, you also have to interact with law enforcement, discover the identity of the attacker, provide enough information to get a warrant, and so forth.
In the whitehat report case, it is as simple as fixing the security hole (and identifying how it got there and how to prevent similar cases) and thanking and rewarding the reporter. However, that wasn't the case here - there was no disclosure, no reason to believe that the attacker was benign, and so an investigation needed to be done.
(I work at Facebook, but not in one of the teams involved in this investigation.)