There needs to be some kind of punishment for failing to take basic security practise into account.
A system where a simple disclosure is enough will probably result in company ignoring security, then when there is a problem they disclose and go on without change.
But, it is also important for the fines to be reduced when taking the right steps to improve. Balancing this will probably be quite difficult.