How about ratifying some law that says, once a company has been warned about their use of unsafe crypto for X amount of time, if they still don't fix things, then they are fair game to black hats (as in, no black hat will be prosecuted for exploiting the unsafe crypto)?
I know it might sound crazy.