Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.
I disagree with this as stated. Maybe in the right context you could make a case for it, but in general? Heck no. Intent matters a great deal, and there is no justice in treating someone incompetent (or negligent) the same as someone who is actually malicious. Both things are bad, but the latter is worse than the former even if they lead to the same outcome.
But is there someone accountable for it being so? Are they malicious? Who is ultimately to blame?
The road to hell is paved with good intentions.
The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.
At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!
I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.
Both are inexcusable, but one is more common/likely than the other.
You can certainly link them together and yes leaders should be held responsible no matter what, but from my perspective as the user who had his data leaked, it doesn't really matter how/why it happened, does it?
Not being held accountable for negligence or incompetence is the evil machination.