We would deploy enormous resources to protect something if IT believed that had a legal requirement to do so (and make a lot of noise about how "secure" we were), but we would leave treasure chests of information sitting around in the open if there wasn't a box they needed to check saying "don't leave unattended treasure chests of private data in the open."
If anything this convinced me that the regulations surrounding this sort of thing are a joke. We don't need rules about security or how to build X - IT will just see a list of boxes, check them, and then ignore everything not specifically enumerated. We need a white hat law for certifying hacking teams that can legally try to crack corporations with sensitive data. If they succeed, the company has to pay enormous fines _to the team that hacked them_ and solve the problem or get their certifications/contracts revoked.