It'll make more sense when you realize that promoting the competence of American corporations is, in and of itself, an explicit policy goal of the American government.
>>CPLX+(OP)
If they wanted to promote competence then the damages would be applied to the corporation for implementing the vulnerability, not on the attacker for exposing it. This way, corporations are given a shield for being incompetent and can place the blame and damages upon an individual that brings them to light.