The thing is that security is a fuzzy boundary, so no amount of case law or statutes can draw an easy-to-understand line between negligent insecurity and acceptable insecurity, and the legal community is ill-equipped to make excellent technological laws.
Also, there's no engineering society that censures its members and creates standards or certifications for quality or security, and it doesn't look like engineers are too interested in that.
Medical malpractice or unethical behavior are also fuzzy lines, but at least there's a medical association that draws some kind of line, determines standards for membership, and censures its members for malpractice or bad behavior, thereby also improving its public image as a trustworthy institution.