I think instead what we need to do is:
A) have “egregious” problem multipliers that stack. Using outdated cryptographic designs? 10x damages multiplier. Using software with known vulnerabilities that was part of the breach? 100x multiplier. Not encrypting data at rest? 1000x multiplier. Etc etc.
B) develop a standard whereby my PII is not allowed to be stored and you only get access to it at time of use (this would also largely solve the problem of the shadow data marketplace).
Even with all that, you could have a security breach where someone has a Trojan spying on all traffic live on the system and stealing that PII once it’s decrypted. So the problem isn’t solvable but maybe these kinds of steps might raise the bar.