Exec Bonuses being able to be clawed back for Security issues is just about the only fix that will have real effects. Anything else will have MBAs believing it's a "next guy" problem, and a obstacle to hitting their objectives.
Though right now the US thinks it's winning the Security Vulnerability Stockpile war, so it won't change the state quo.
Europe is implementing a law that requires software made for profit to hit at least industry security standards. Punishments include the purchaser being able to sue the seller as well as jail time for execs.
At some point, we need to push back against the reality in the US that we have effectively no way to stop mass harvesting (and then breaching) of our PII -- and there's basically zero downside to companies when it happens.
And how do you enact exec bonuses being clawed back? They're often the most connected people in the company to those setting the rules of the company, the board.
Hell, some companies have a CEO that has an absolute majority of voting power, meaning they cannot be held accountable and made to implement changes like the one you suggest.