There should be a carrot and a stick solution with a regulated baseline of security (such as "don't use hardcoded passwords, dummy!").
Carrot: labeling/rating system ("our IoT device is A+ security rated, best in class!")
Stick: Devices found part of a botnet and/or DDoS attack are taken offline permanently until cleaned, and/or recall mandated by the governments.
That ought to be enough to improve IoT devices security by about two orders of magnitude from what it is now.
The nice thing about such regulations is that now manufacturers don't have to race to the bottom on costs by not increasing their devices' security and updating them. Because they could win more sales through good rating systems or they could lose much more money through recalls, being shut off from the Internet, and therefore potentially losing customers permanently, and so on.
I'm a believer in "free markets with good baseline standards" for competition, fairness, consumer protection, etc.
I'm not entirely sure how support for updates should be handled, but I think it should be mandated that until at least 80% of your customers stopped using your product, then you are still liable for updating all of them.
So, for instance, if 30% of your customers still use your "smart fridge" 10 years later, then you should still send security updates to it (within 3 months of bug discovery). If after 12 years, only 19% of your customers still use it, then you can stop updating it.
Even then, I worry that 20% of IoT devices could mean potentially billions of devices 15 years from now. And they could still be used by botnets. But hopefully by then the Internet would also be a lot more resilient to DDoS attacks (perhaps by decentralizing it more) and a couple billion IoT devices embedded everywhere into our cities won't represent that much potential DDoS firepower.
EDIT: Whatever made you think this was "voluntary" of Hangzhou Xiongmai? The FBI and likely the DHS and the NSA were investigating this issue. They probably at the very least felt some pressure from them to do this recall. After all, the U.S. government has often been quite decisive on banning Chinese companies from selling in the U.S. because of "national security reasons", so it doesn't seem unlikely that this company feared the same could happen now, too. From that perspective a recall seems cheap.