I wouldn't be surprised (or disappointed) if some enterprising company developed a security certification (a la PCI) for Bitcoin-related providers. You wouldn't _have_ to offer it, but the market might favor those that had subjected themselves to that scrutiny.