The physical world and the Internet are completely different environments, and analogies don't transfer. In the physical world attackers are resource constrained, create evidence that allows for attribution, post-facto enforcement is mostly successful, attacks are mostly destructive, and security can only ever be "good enough" bar.
Meanwhile in the electronic word, many attacks can be easily scaled/automated so they're always happening, attribution is very hard, there's little post-facto enforcement especially across borders, most attacks don't do much damage in and of themselves, and most security problems are logic bugs which are yes/no affairs.
It's not particularly interesting if a "white hat" physical attacker demonstrated they could get into a safe with a drill over the course of a week. And one probably can walk down a street testing businesses' doors after hours without too many repercussions if you're dressed nice and don't fit the cops' stereotype of "criminal".
Also there's a huge tendency in the digital security world for system owners to play up damages from minor break ins or even mostly innocuous actions (eg port scans), to distract from the humiliation of themselves having failed. And if we did want to make punishment more in line with real world analogs, then the penalty for most unauthorized accesses should be akin to misdemeanor trespassing.