I was thinking, would it be a viable solution for the government to employ pen testers to test companies like banks/ISPs etc? It would more than pay for itself from the fines they would impose to those that hold sensitive citizen data and fail to hold high standards of security.