Re: Stop paying. Stop making excuses for piss-poor IT.
I'm probably close to being one of those security people that annoy you, and I will say that, because no matter how much I might want to do all of the things you want (very much yes on most, but not all), I don't get to. I can't make ransom payments illegal, even though I think that doing so would be the biggest and only thing we could do to make a dent in ransomware. I'll continue suggesting it, as I have been doing for at least five years, and until that ends up convincing politicians, I have to deal with the situation where it isn't illegal and I can't make it.
That applies to anything about who is liable; it's also a legal thing I can't do anything about, but there is a reason I'd be cautious. Any time the suggestion is to find someone, the CEO or otherwise, and drop a load of bricks on them when something goes wrong, there is potential for that to backfire. No law would ever be that extreme, if only for the situation where the CEO approved a massive budget and some incompetent or malicious IT person failed to use it. Which means that there's always some chance that the person who gets all the blame and suffers the worst consequences won't be the CEO, but whoever the CEO's assistants can best pick as the scapegoat, which will be much easier for them than it will be for the scapegoat to turn around. The people I've seen suggesting it always manage to phrase it so they won't be in the crosshairs, which is unjust as they might actually have some responsibility for it, and even if we decided that was the best of the bad options, you can't successfully enact the "CEO is always responsible, IT never is" law. There are many risks in an enthusiastic blame game and so, even if I could pass that law just by saying it, I wouldn't suggest doing it with that severity.
I'm not exactly sure what "wage decimation" you're referring to, but if the company has decided to outsource, then I don't get to tell them not to, and if I fail to convince them that there's a risk big enough that they choose to do it voluntarily, then what do you suggest I do? I can either do my job: secure the outsourced workers as best I can, or I can refuse to do that and quit, but I can't make them not outsource, and in many cases, this isn't a security problem, so I wouldn't be consulted in the first place.