"Defcon A transit agency in New England ..."
"The Massachusetts Bay Transit Authority (MBTA) also named MIT ..."
gosh, you would think they would just be happy with MBTA.
Well, they really don't know how all of this works do they.
Now it has been mentioned, people will find the flaws, suing is no defence, it is just a way to paint a great big bull's eye on you.
Company's don't want to pay for IT security, it is that simple, stick up a website offering computer security, and watch no one will ask for your services. Unless they get compromised. You will have to approach, and pitch the fear of god into them.
It is because it is a new thing, and not something people cost into business.
You can get work, via insurance companies, but really it all centres around the compromise. Banks have it, but they prefer to keep in house. New innovation does not go through a security process, and you really have to mention it to clients for nearly any tech, and they will umm and ahh over it.
They think the police should protect them, that is what they pay their taxes for.
There will always be people interested in computer security, but I don't think it will ever have a bubble unless those same people are out compromising systems, which is a fairly risky business proposition. Forbidden knowledge really, I think most business owners would prefer no one ever knew about it, it can only cost unless used in industrial espionage, and that is illegal so not something you can really promote.
At some point the insurance companies, will put a figure on it, but even then you have the problem of the thing changing all the time, it is not quantifiable, it is not like a crash test dummy and a safety belt, or even a safe, it is far more complex. That's why people buy anti virus, sure they will kid themselves it does something, and to a degree it will protect, but deep down they know they do it so if they do get compromised then they can say they had some protection, and for 50 quid well it affords them that statement.
So, only way to make money in the game is to publish the exploit, then let all hell ensue, see if you can get paid to fix it. Yes you have to be a bastard about it, there are no really good guys in security who make money, it is all about fear and exploitation, whichever colour hat you think you are wearing.