"The same needs to happen in security"
I agree completely.
The only problem is that, when an airplane crashes, deaths are involved and the number of specialists that analyze the issues are limited and highly experienced.
In the world of computing, a company cannot lock down a server for a full forensic examination, it needs to continue making money and it didn't foresee the expenses for a second server with the same configuration to pick up where the hacked one fell off.
Computer security is hard because you can be hacked without knowing it. If a plane has a problem, the pilot will find out and report it, and there's every chance the problem will be corrected.
Plus, in computing the experts are not always that experienced and they don't have the same moral incentive to find all the truth. So, 35 million records were downloaded ? Yeah, but no one died. It is quite possible that some people will be inconvenienced, some of them severely, but no one died.
I agree with the spirit of the idea, but if the industry took security seriously we'd already know.
Still, it doesn't do any harm to speak about it.