There needs to be some kind of punishment for failing to take basic security practise into account.
A system where a simple disclosure is enough will probably result in company ignoring security, then when there is a problem they disclose and go on without change.
But, it is also important for the fines to be reduced when taking the right steps to improve.
Balancing this will probably be quite difficult.
Executives can already go to jail for not reporting vulnerabilities. The risk of personal criminal liability is one of the reasons people choose not to move into the Director role, in big tech security careers.
But, it is also important for the fines to be reduced when taking the right steps to improve. Balancing this will probably be quite difficult.