Let's not pretend we do not all -know- virtually every company looks at security as a cover your ass exercise. The SaaS is able to provide some fort of "certification", so companies are happy to move responsibility to them.
They don't actually care about protecting PII or anything.
The problem is that all responsibility being moved is who gets to shrug. There need to be nontrivial per customer damages paid for each such incident.