
At what point do people start taking information security seriously?
I used to think that once big companies started losing big money the shoddy practices would cease, but apparently not: here we are. I also think that software developers need to be (more) regulated, such that a developer asked to (or under time pressure) create shoddy or ill-tested code has the backing to say no, in just the same way a civil engineer asked to create an unsafe building must say no. However, I don't see that happening soon either.
What, then? When will people with clout (e.g. business owners, regulators, investors) say enough is enough and do something to stop the plague of crap code and crap security practices? (excuse the french, please :)