That is on the company indeed -- except in these cases the company usually tries to find on whose individual head it might deflect the blame.
But it's hard to teach people about sensitive information on a personal level when it is ignored on a daily basis at work.