We need a cultural shift, security should not be a whimsical dream. A company running vulnerable websites should be culpable for their neglect, and likely shouldn't be administering their own IT affairs if they are repeatedly negligent.
This is an anti-China move, but we do know Huawei builds vulnerable LTE basestations and products, and refuses to do the bare minimum to secure them, despite promising $20 billion in investment in software security (see the article I linked to earlier).