> The actual problem is management doesn't care about security with no financial damages for that in most cases. So, they don't try to secure the project.
Nor should they, if they act rationally.
To be honest, I've started thinking that having a lot stronger regulation for punishing companies is the only way to improve the situation. GDPR is a good start in the EU, although it is privacy-focused.
The free-market solution to this is that users (be they consumer or B2B) start shunning the companies and products with the worst security records, but the problem is that security (and privacy, it seems) are so hard to grasp that it's just not happening. Companies exist to make money, and it's sad how many of them won't actually care about anything else. So if that is the only thing that they care about, the only option to make them care about security is to make insecurity a bad road business-wise.