The Irony is their actions on remediation are almost exactly in line with the decisions made that often times lead to the incident. It's cyclical.
With often vague or only theoretical damages, it's harder to muster support for draconian consequences.
Also people can sort of understand accounting. Dollars and cents and balances are something most people can comprehend. Computer software and security breaches, on the other hand, are much more of a black box for most people. They can't intuitively understand what's sensisible and reasonable and what would constitute negligence when it comes to protecting software sytems and data, other than by relying on what other people tell them.
It would not be a bad strategy at all to leak the names of as many potential scapegoats as possible if one were avoiding accountability.