The US critical infrastructure security is known to be completely lacking, which is a shame.
The Federal government needs to tie all types of grants and funds to these kinds of institutions to compliance with security regulations and best practices. Withhold funds until the issue is fixed.
Network security however isn't a big deal to most though, you can see that even with private companies that do most business through the interwebs, they refuse to adequately staff IT departments nor pay for qualified people.
It's why groups like Anonymous are able to inflict so much damage, most everything out there is wide open. I used to be a big opponent to the whole attacking a company or government agency to show how weak their security was and to force them to fix the problem, it however seems like that's the ONLY way to force these companies and agencies to make any changes.