I think John's point was more wide-ranging. Even without regulation, the truth is that security has long become just another market, where vulnerabilities and skills are bought and sold for cash, like any other commodity. Security used to be an aspect of system administration; now it's just another rat race with all the trappings of commercialisation ("enterprise" products etc etc).