Far better if they instead pass laws that simply mandate certain types of companies conduct regular security audits by their choice of external auditors, coupled with penalties if those audits find that the companies are not following established industry standards.