It also ignores the point from the article that the solution can't be trying to make all software secure. Whatever the incentive mechanism and whatever the source of the insecurity, it's unrealistic to think we're ever going to be able to make that a reality. But designing the environments software is used in such that broken software isn't the end of the world seems doable, if also incredibly difficult.
For that matter, even considering to use components that unfit for purpose is inconceivable in most professions. Only in software do people use systems with no specifications, no guarantees, and where even the component makers did not intend or design them to be load bearing.
That said, it's often easy things that get the most benefit and we are collectively a long way away from getting the basic security things done properly across the board.
They are already paying for it, and not getting the security.
Particularly in reduced competition due to deep pockets being required to even play the game.
It seems like a fine structure would have to take that into account? Or am I way off base?
We wouldn't have the level of tech we have today if we were to require 'mistakes to be impossible', Rapid growth requires mistakes to be acceptable in some situations.
On the other hand, a quality needs fines. Otherwise, it's too easy to "forget" an inconvenient quality to make a short-term profit (and sometimes compromise users data).