I wonder if you can get a recourse from the customer care. Corporations are simply not investing in security practices – basic issues around lack of password managers, lack of security sticks (like Yubikeys) and not enough shared responsibilities between CTO and CEO. I’d reckon that if the C-suite is accountable for these breaches (or any type) and makes mandatory disclosures, the problem will be scuttled along with heavy punitive fines.