> Consequences like that will mean it makes financial sense to ignore security and just pay the settlements as they come.
If judgments like this were the only reason to prioritize security, then sure. But hopefully there are at least some market/reputational forces at work too.
The Ashley Madison Breach comes to mind. If the core demographic cares about not wanting their data on the platform to get out, they will vote with their feet. That said, I think this example is not the norm, and most people probably won't care for most applications.
https://en.wikipedia.org/wiki/Ashley_Madison_data_breach
I mean wasn't it also revealed that an overwhelming amount of people on the site were male in the same breach? Id guess that would be a motivating factor more than the privacy