How could you possibly make it illegal to host insecure services? Is any service 100% secure? And if it were how would we know?
I do agree with the audit and punishments for clear failure to adhere to established standards.
"established standards" - now who has the incentive to run shitty services? those big enough to control the "established standards".
No building has a 100% chance of not caving in, yet somehow I think charges would be laid if a skyscraper caved in.
This is a solved problem in pretty much every other domain of life - if you are following best practises but something that wasn't reasonably forseeable happens, then you're fine, but if the bad thing happens as a result of negligence then you are in trouble.