I think you fail to mention that public disclosure of security holes is also an option to force companies into action.