Here is an interesting one to discuss?

The idea is that it should be the entity who allowed its secure data to be compromised should foot the bill for the consequences, rather than the financial institution or customer thereof:

http://www.boston.com/news/local/mas...n.com+%2F+News