This is a side note about your example, but you say "Banks care about information security and take it seriously. They use a crappy contractor called Equifax which doesn’t." If banks send important information to a contractor which they're unable to verify takes information security seriously, then it's hard to see how the banks can be said to be taking it seriously.