I would assume that a CSO at a F500 company is mostly responsible for things like budgeting, hiring, and high level strategy. I would think not knowing these specifics is reasonable. What isn’t excusable though is these companies ignoring advice from internal and external sources. Companies clearly make deliberate budget choices by weighing risk/reward and a CSO at a big company often rationally doesn’t make the right security choice because the risk is small. IMO, bills like this are needed in order to force companies to properly value the risk of bad security.