The point is exactly that- morality isn't for "extra credit", we shouldn't need to get rewarded to do the right thing- that's kind of the point.
I mean sure, maybe when it comes to smaller companies. But some of the companies with the biggest security blunders are those that have enough money that the security for their users information should be a major priority and those costs would barely impact their bottom line.
And also... Using this same train of argument couldn't we also just argue that the cost of security compliance shouldn't be this high to begin with so it's more accessible?