No, I support privacy laws. But this is a different issue with different circumstances. Adhering to privacy laws IS a burden on business. However, protecting themselves from cyber attacks is in their own best interest. Why would businesses continue to do something (or not do something) that causes them harm? That's why I believe it will happen without a law punishing victims. I don't necessarily support the "status quo", I just don't support your solution. I'll never support a solution that basically says that if I am held at gunpoint and give a thief my wallet that I am going to go to jail.
Until businesses have actual technical solutions to these problems in place, adjusting their current policies and processes will only help them to go out of business if they are the victim of such an attack. We don't need a law protecting businesses that are unwilling to protect themselves. If they are unable to protect themselves then a law won't help them if they are attacked and will be of questionable effectiveness in preventing such an attack. As long as attacks are essentially as easy as a phishing email, lessening the chances of the attackers getting paid isn't really much of a deterrent. They'll just make it up on volume. Somebody will still pay, regardless of law.
RE: Paying Ransomware Should be Illegal