These standards that are out there aren't difficult to implement or put in place. For example if we look at PCI-DSS standards some of them include
1 - Changing default passwords
2 - Having a firewall
3 - Encrypting PCI information at rest
4 - Using encrypted communication channels for PCI (https).
This is just some of the standards and none of them are very hard, all of them are trivial to implement.
So sure it's a bad thing if you get robbed while out on errands, but you're going to get a whole lot less sympathy if it turns out you left the front door open with a sign that said, "I'm not home right now."
EDIT:
To be clear I am not talking about SMB mom and pop shops necessarily in this comment, I am talking about the massive Fortune 1000 companies that are getting hit with this over and over again.