All this talk about software (in)security within companies reminds me of a typical conclusion after a data leak. When it's a large company, the conclusion is they may, and should, have done better, but it's inherently impossible for a large company to secure everything well enough. When it's a small company, the conclusion is they should have done better, but it's inherently impossible for a small company to, well, do better, they are too small.
Now, I'm all for treating ransomware, and generally all the large scale and/or state-sponsored hacks with a much higher priority, send the drones and whatnot. But this MUST be accompanied by more accountability on the commercial entities.
You're too small to secure sensitive data of hundreds of millions of people? Maybe you shouldn't have amassed this data in the first place. You're too big to secure everything? Well, did you secure ANYTHING? Did you follow reasonable procedures, did you, crazy idea, make sure you can't access critical systems from the internet and/or with a default password, etc.?
And if you fail, and fail you will, there's no perfect system, I believe there should be penalties not for failing, but for not doing enough to prevent it. To refer to all the plane analogies, if your wings are made of cardboard and everybody knew but pretended it's OK, because otherwise it would slightly diminish shareholder value, well, there will be consequences.
In aviation, you could go to jail for signing off on something that you know is not secure, if it causes an accident and people die. Specifically not for accidents, but for neglecting your duty to make sure that you've done all you could. For lying, deceiving, ignoring, faking, for being too lazy or too greedy to do things properly. Sounds familiar?
With large scale infrastructure under constant attacks, people dying because someone couldn't be bothered to do things properly is not an "if" any more. And better hope those autonomous trucks are very, very hard to hack.