I'm not sure whether I really agree with the singular focus on the CEO or C*O, but often one of the reasons that is given for their large paychecks is that they carry a lot of responsibilities. Following that, it would seem prudent to actually hold them responsible when something goes wrong, especially something with as much impact as a large-scale data breach.