There's 'compliance security' and then there's 'street-smart security'. They are very different things. Most organizations aim for compliance (it's cheap and easy). They base security on contracts, certs and insurance policies. Street-smart security practitioners are appalled by this. And, management doesn't understand why the 'security people' aren't on-board with 'compliance'. It's a lot like the old west with Cowb…
Pretty sure you hit it on the head. Over time, security breeches should alleviate this gap.
Yes, Anthem/BCBS, Target, HD, Sony, etc, etc have all had losses.. but they really havent been long-term impacted it seems.
I dont know what the answer is, this sucks hard as both a consumer and an infosec person. I tend to view security as a "hidden performance" factor. As long as the security flaws don't inconvenience the paying customers too much, they simply don't care if they exist or not.