On Monday, a federal appeals court ruled that the Federal Trade Commission (FTC) has the power to take action (PDF) against companies that employ poor IT security practices.
Link: FTC can sue companies with poor information security, appeals court says