That would be a mistake because it also incentivizes hackers, making the problem bigger on that side. What I would like is something that punishes companies that get hacked as well, like set fines for leaking personal information instead of settlement. People same to take GDPR seriously, a similarly stringent regulation on security practices would be effective.