>
is suddenly a capital offense because...Whoppers might run out?We know the stakes are much higher. We all know there have been attacks on hospitals, law enforcement systems, government agencies, infrastructure companies, etc. And, we know that none of us have a clue where the next attack will be.
>and stupid legacy cruft that is modern software development
Yes, modern software development is stupid, crufty and all of those things. But, these are actual attacks by actual actors, not some self-imploding poor designs. In many cases, these attacks are state-sanctioned, if not outright state-sponsored. So, of course they should be treated just as we treat other attacks. And, under what other scenario do we respond to an attack by declaring "Oh, you got us. We should have better protected that".
These are clear national security threats and should, accordingly, be subject to the full range of responses as any other threats. That includes deterrence. It doesn't necessarily mean dropping bombs. But, it does mean more than blaming ourselves.
>Diddling around in the network of a company you didn’t know existed until five minutes ago
I'd wager there are many companies that the average person has never heard of that, if knocked offline, would result in considerable disruption, economic costs, and even physical danger to a significant portion of the population.