Sounds good. Let's also assume data-driven decision-making.
> failing to (a) appreciate the damage a security vulnerability (or exploit) can cause
As far as I'm aware, neither of these is known to have resulted in damage yet, so as far as I'm know there is nothing to fail to appreciate.
> failing to (b) receive timely notice of said occurrences
This is a problem if and only if the above damages actually do occur more quickly than the people in charge have time to act. So it loops back to the above. _______________________________________
EDIT: It seems everyone is misunderstanding my point. I'm not looking at this from the standpoint of either of the parties. Yes, they can sue for damages, and perhaps they even should. That's perfectly fine! That has nothing to do with what I was trying to say.
Rather, I'm looking at the problem from an 'outer' standpoint -- the same perspective I would assume a lawmaker would have (or at least should have), which is the perspective of: "Is the system able to handle its problems?" If the legal system can already handle this "exception" and sort out the problems and hand out appropriate penalties for everyone involved, then the system is working as designed, i.e. we fail to have grounds for e.g. requiring early disclosure. On the other hand, if people who are not parties to the case are getting hacked and/or having their identities stolen, then that is a failure of the legal system that needs to be addressed, e.g. by requiring timely disclosure.
Basically, the fact is that we all like timely disclosure (myself included) and yet we are failing to explicitly show what problem exactly it would solve. So far, it is not clear that earlier disclosure would have prevented any problems that we are already seeing. If and when we get solid data to that effect, then we have grounds for blaming lawmakers and demanding change.
Damage as in malicious? No. Damage as in co's reporting higher instance usage on cloud services after patching? Yes. Don't discount companies being angry about higher hosting costs and taking it out on Intel via a financial damages suit.
Playing devil's advocate a bit here, but you could also think about it differently. This whole time, faster-but-more-insecure processors were providing everyone with cheaper prices than they would have had otherwise with more secure processors. I feel your notion of "damage" is far weaker than mine.
How many sysadmins have been working overtime to investigate this, deploy out of band patches, and test their impact on infrastructure that may now be underprovisioned? Meltdown and Spectre are already inflicting serious costs even before exploits are found in the wild.