A better system would be one where the company paid a fine starting at $500 per record. Also, not all consumers who have had their data stolen gave it to the organization willingly.
Completely agree on this. A company-killing level of fine, based on number or records exposed, is appropriate. Then the insurance companies would not ensure companies unless they passed stringent audits around best practice and data hygiene.