Jason Spaltro, then executive director of information security at Sony Pictures, called it a "valid business decision to accept the risk of a security breach" in a 2007 interview with CIO Magazine, adding he would not invest "$10 million to avoid a possible $1 million loss."
So basically their thinking was that getting hacked was just the cost of doing business. Of course, they are now discovering that the cost of a really serious hack is much higher than they thought it was.
Which makes me wonder if, at some point, we're going to have to have some kind of controls on who can legally hold personally identifiable information on their systems and who cannot. Right now pretty much anybody can, regardless of whether they're competent enough to protect it. And as a result there's a huge volume of critical information out there stored on systems that are either poorly secured or whose admins have decided, like Sony's, that the ROI on real security is too poor to justify having any, which creates a target-rich environment for hackers to take advantage of.
Attaching serious liability to holding data on systems that aren't secured, or requiring proof of competency/minimum-acceptable-effort in order to avoid such, might shift the ROI calculation on security enough to convince even idiots that it's worthwhile; or, at least, that it's better to outsource holding the data to someone who knows what they're doing (and is willing to back that up by accepting liability) than it is to keep everything in-house on a dusty Windows NT4 box under someone's desk and just cross their fingers.
We already sort of do this sort of thing for financial information, via PCI; but the universe of "data that could do serious damage if it got loose" is much larger than that which PCI covers, as this hack demonstrates. So I wonder how many of these types of giant hacks people will be willing to accept before they start calling for some kind of protection.