No, liability requirements force banks to be held accountable. They do eat most of the costs of the direct consequences of being hacked. Luckily for them, the people hacking them are still, frankly, inexperienced from a business perspective so their losses have to this point been largely immaterial.
The losses are not low because the cybersecurity processes and regulations are good, they are low because even though the vault is being guarded by the metaphorical equivalent a chihuahua, all they are doing is stealing the pens because they do not know how to pawn the gold in bulk.
This state of affairs is changing very quickly. 15 years ago the hackers were walking into the vault and asking for $1,000 because they were 16 year olds who thought that was a lot of money. Now the good ones are 30 years old and are still walking into the vault, but asking for $10,000,000. Last I saw the number of attacks was increasing 3x year over year and the average ask was increasing 3x year over year.
The entire cybersecurity insurance industry is already underwater at current premiums. I have heard they have basically stopped issuing policys over a few million dollars because it is literally ruinous. It is no longer becoming possible to paper over the omnipresent security deficiencys with insurance, betting on the incompetence of the attackers, and betting only one of you is going to get eaten.
The sensible solution right now would be liability requirements on advertising security. You can not insinuate you are “secure” whatever that even means. You can instead only advertise a dollar amount per customer which is tied to a mandatory bug bounty. If you are a big bank with 100 million customers, you can put up a 10 billion dollar bug bounty on breaching your systems and then you can advertise $100 of security on your customer deposits.
This would force them to put their money where their mouth is while not preventing new small companys from existing as long as they truthfully report that they are not providing security. It would also help us pull the customer desired security requirements forward in time instead of waiting for the destruction first.
Absent that, what is going to happen is that everybody keeps lying about their security to trick their customers into trusting them. Then one of them is going to get hit by a truly expensive attack and all the customers will be caught with their pants down.
The only technical solution to this is either dropping reliance on these easily hacked systems, or throwing out all the existing crap that was never designed for security and can thus never be retrofitted to be secure such as Microsoft, Linux, Cisco, and Crowdstrike. Instead we must deploy systems designed for security such as those targeted to conform to the (now deprecated) Orange Book Class A1 or Common Criteria EAL 6/7 systems which are certified and proven to resist nation state attackers such as the NSA.