There should be fines big enough to bankrupt the companies who fail to secure data this kind of data. Is there some other way to convince them to take the issue more seriously?
...and then when their assets are broken up and sold off in bankruptcy, your sensitive data ends up scattered to random companies you never heard of.
I would rather that there be greater security training in software development programs/bootcamps.
I’m a software engineer. I know a lot of software engineers. None of us have ever been trained in security.
Any “best practices” are usually picked up in Stack Overflow conversations.