The Equifax hack(s) have resulted in impassioned discussions on security, patching and due diligence in general. Many CISOs and security stalwarts have had a lot to say on the matter and yet we don't see any security leaders actually wanting to work at companies like Equifax.
So I am curious to learn what would it take for the security champions to be enticed into working for Equifax et al.
Equifax failed at security because Equifax's leadership doesn't care. They will only be convinced by seeing revenue drop or incurring larger penalties from the government. Revenue will not drop because the affected people are not paying customers. Penalties will not increase because the current political climate is "All regulations are bad" when it should be "Bad regulations are bad; Good regulations are good."