None. That's part of my point: the root problem is not actually security by itself, it's bad corporate governance. CEOs should be fired for such things, but they're not.
> If the "free market" doesn't care
Corporate governance is not a free market nowadays. It was more of one in the past (although an argument can be made that there were important non-free market forces even then), when most stock ownership was in the hands of individuals who at least had some incentive to hold boards of directors accountable for long-term stewardship, since they were investing with a long time horizon for their own retirement.
But now most stock ownership is in the hands of large mutual funds (since that's where most people's retirement funds are now), which don't care about long-term stewardship; they only care about short-term earnings. So corporations have a positive incentive to overlook things that, to be fixed, will require sacrificing short-term earnings for long-term stewardship. Individual investors never even see this; all they see is the overall rate of return of their mutual funds. So they don't realize the long-term consequences of what is going on and aren't able to apply free market incentives to correct things.
That's probably a rounding error on their quarterly report. Heck, it might have cost them more money to hire more people to provide adequate security to prevent such attacks than to just suck it up and get attacked.
It may actually be economically favorable to stay insecure!
If that were the case, the market would actually encourage CEO's to spend less money on security, not more.