Well, maybe more checklists and consultants.
It may not make more revenue but poor security certainly affects profits.
What we need is regulation regarding putting personal data at risk to provide a financial incentive for companies to take security seriously.
If you do an in-depth read of the PCI security standards, you’ll see that the standards are about protecting the card brands, not you.
Risk is free.
A risk-aware competitor faces a higher cost function and a market which won't support it.
What we need is regulation, and direct liability of corporations, stockholders, creditors, and executives.
"A stitch in time saves nine" is probably more relevant to security.
Fines would therefore be the obvious solution to the lack of cybersecurity. Network breach / data leak due to not patching software x days after vuln disclosure? Here's your fine!
I believe the real problem is effective security is hard, and most merely want to pretend than actually invest in doing it.