Ah I understand now.
A fine is a bad idea since companies should be able to take risk freely as long as this risk isn't socialized. I don't get fined for leaving my door unlocked, because it is my prerogative whether I take that risk. If risky behaviour affects others, then fines would be appropriate (e.g. managing customer data)