Proper Regulation
The question is, can there be useful regulation, which will make systems more secure ?
Innovation, efficiency, security must be balanced. It does not help to set up a soviet-style bureaucracy because of security issues.
One idea would be that government mandates Payment-For-Exploits for all systems in wide use. For example, SAP would have to pay whitehat hackers for finding bugs in SAP/R3. Microsoft would have to pay for bugs found in Windows. Then the question arises, how large is the finance pool to be paid out to security researchers ? Maybe 3% of sales revenue ?
Of course, companies must also be forced to make these systems available to qualified researchers. So IBM would have to make their mainframes available to skilled software engineers. Same with SAP/R3, Oracle ERP, Windows Server and so on. Inevitably, some sort of state bureaucracy must administer this. It must be staffed by skilled and motivated civil servants. Could NSA, BSI or CESG do this ? Possibly, if we want to make the fox the master of the henhouse ;-)
Widely used FOSS software would have a state-paid exploit payout pool for the same effect. So USG would cough up 30 million p.a. for Apache Exploit Research ? How would Japan, SK, Britain, France contribute ?
Maybe the software tycoons have a constructive idea on the matter ? (Seriously)