Earlier quoted context omitted.
I sympathise with your frustration, but the blame is absolutely with your bank. I mean, finances are like THE thing to be security minded about - the fact they're still using IE is just unacceptable from any lens.
Sometimes the blame is regulations: too many hoops for banks to update their software easily and without adding stupid regulatory liabilities. Regulations added to protect the user, but perversely hinder the user.
No, regulations do not incentivise bad security practices at all. In fact, they are one of the only tools to enforce good security practices.