I take your point --- if you're ostensibly made of money (NASDAQ is more or less a "tier 1 ISP for money"), you should just be able to spend more money to address this problem.
However, as important as security has become in the last several years, the strategic scale of the problem really hasn't sunk in at the highest levels of most companies. Operations and development are still adversarial to security, they still run the table, and all three of these groups (ops, dev, and security) are still considered cost centers by COOs.
That doesn't mean they're not important, of course. Any cost center that didn't perform an important function would just be cut. But it's just like running payroll -- it would be disastrous if you couldn't do it in a consistent and timely fashion, but as long as everything seems to be working correctly, nobody outside that area is ever going to care that much about it.
1. Revenue center model
Currently we have no computers. If we build a system that securely allows financial transactions, we can make a lot of revenue. We will assemble a team that builds a secure system for financial transactions.
2. Cost Center model
We will build a system that handles financial transactions. That will be our revenue center. The system will not have security as a requirement. Then we will have a cost center that is responsible for making this system secure.
PHB: Which costs more? Option 1? Ok, do option 2 then. Build me a system that isn't secure first, and then we'll work on that when we can.
Meanwhile all the other experts suggest not touching a high performance, high throughput system by immediately installing every new patch that arrives.