Fines are too easy..
It's not like the threat isn't known by now, so executives who either choose systems based on nothing more than a good game of golf or expensive lunches or refuse to fund good security policies, processes and associated technology ought to be fined directly, and companies that despite literally TERAbytes of 'patches' still can't get their sh*t together should no longer be able to avoid liability, regardless of what their Terms state.
If you get yourself declared 'critical' (read: get a de facto monopoly status handed to you) you should be compelled to accept the associated responsibilities that come with it.
No more BS.
There. I feel better now :).