Somehow this is now a negative stance, but what other incentive is there to not just spend 0$ on security? Write crap software and get hacked, blame law enforcement for not getting the criminals.
I think the problem is security in the software industry is not compatible with the US' volume production style economy, so more spending will be on more low/no assurance software that matches more checkboxes, raises costs and further deteriorates security. Companies that minimize their attack surfaces will be the only ones that cease to qualify for insurance under most legislation that would appeal to the industry.
Victim blaming won't help here. Ransomware is generally a sophisticated attack by groups that tend to have the finances, skills, and resources to stay ahead of 80% of the companies operating today.