Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior security gurus on $300k /yr with 60 vacation days, and letting them bring in a team to deliver meaningful security.
Beyond taking security out of the hands of bean-counters though, I'm not sure how you address this. Pursuing organisations that pay ransoms and prosecuting senior CEO/CFO-type executives for conspiracy to commit money laundering (and pushing for criminal convictions) could discourage paying ransoms. If it's left to businesses as something they can write down as a "cost", I don't see it getting better - there has to be a risk to the liberty of the CEO/CFO before they'll take security seriously in my experience. 90 days in federal prison would certainly sharpen their focus in future.