No. They should go further. We should have a law, similar to Sarbanes-Oxley, that forces companies to undergo a security audit every year.
Otherwise, we're going to be in an endless cycle, where companies refuse to invest in security, a huge breach occurs, and everyone suffers.
The current system does not incentivize investments in security because they hurt the bottom line and have no tangible, immediate value to shareholders. That's a dangerous situation.
I'd rather see some security standards (updated yearly or so) and heavy fines and reimbursements after an hack (not necessarily malicious - proof of concept published by a white hacker would do), if the security was lax. Triple them if the company hid the fact that they had been hacked.
Fining companies heavily for being hacked is like fining someone for being rained on. Except, in this case, the rain is pretty much a guarantee, and the person knows that, and when they get rained on, their customers get screwed. So you fine them for not having an umbrella.
An audit doesn't necessarily need to be done the way it has before. It could even just be a bug bounty hackathon, like the big browsers do.
If whitehats had a ton of easy-to-find work to do, there'd probably also be fewer blackhats.
If security audits were to become mandatory, they would only apply to companies of a certain size.