There's a perception problem: "being hacked" means you are a victim, and the question of negligence rarely comes into play. There should be more stigma associated with it, so that someone who has a serious security problem is seen as the lax/irresponsible party to a breach that they really are.
My reaction is similar. Specifically, I recall reading a few years ago some stories/comments about differences between banking in the U.S. versus Europe. For example, IIRC, one reason Europe had... I believe it's called "chip and PIN" on banking cards, was/is that banks are financial liable for losses.
Occasionally, a good article will appear that discusses "risk". I've come to assign great relevance to the term; many circumstances and changes "make sense" when you look at where risk is or is being shifted.