@GossiTheDog You got GDPR because companies didn't really have much incentive to care about mismanaging personal data/severely impacting the lives of their customers.
Aside from NIS/new CS+R bill, one assumes it was felt there wasn't really the need to legislate the operations part/"perhaps don't let your company burn down" potential scenarios as you'd usually think a CEO is primarily focused on exactly that anyway... turns out we were wrong. Getting to the next end-of-quarter bonus seems to be more important than checking whether the company is still there or not.