It also helps to look at the other end: minimum cost to stop most problems. Australia's DSD said that just patching stuff and using whitelisting would've prevented 75% of so-called APT's in their country. Throw in MAC-enabled Linux, OpenBSD, sandboxed (even physically) browsers w/ NoScript, custom apps in safe languages, VPN's by default, sanest configuration by default, and so on. Residual risk gets tiny. What I just listed barely cost anything. Apathy, which the article acknowledges, is only explanation.
A nice example was Playstation Network hack. I didn't expect them to spend much on security. I also didn't expect it to come down to having no firewall (they're free) in front of an Apache server that was unpatched for six months (patches are free). That this level of negligence is even legal is the main problem.