But its like there is a guy on the floor bleeding and we say, unless everyone is going to help i will not

Not sure that's the most fitting analogy, Melih.

We must do our bit! And as we get more people, the market will be forced and this will be a best security practice that businesses will have to do.
The scenario I laid out happens all the time and it's not just small businesses, it's also those that have internal auditors vetting security of their computer systems as they are developed. (And external auditors periodically) Why are these insecure practices not picked up? It appears that there is less accountability on the WWW where the need is far greater than there was on mainframe systems in the past.
Although it's impossible to police the web itself, many individual countries do have the powers in place to enforce best practices from companies and take necessary action against those who do not comply.
So why is no action being taken?
Silly question really, when Government Departments in the UK allow account details of all individuals claiming child benefit to be sent on unencrypted CDs via the post and lose them.
Regards, V