Amazing that all publicly traded companies are not by law required to have bug bounties. Same goes for any major open source project too.
We probably agree that vulnerability reports should be seen as a positive thing. What software owners should have are policies and procedures for transparently handling vulnerability disclosures. At most, I think having some flexible process should be required as part of a certification (PCI, etc).
I do think that knowledge of a vulnerability and lack of action to fix it in a reasonable amount of time, which results in a breach should be treated more seriously. At the same time, encouraging reports of breaches is hard as it is and introducing more punishment would make everyone want to just keep quiet or as ambiguous as possible. I'm not sure what a good solution to this would be.