Your anecdote describes a very bad behaviour, but the generally simple requirements banks have is a necessity of dealing with the general public. The more complex the requirements, the more customer support with tech naifs you need. And overall, it generally kind've works for them; there are some slips through the cracks, but fraud isn't rampant - banks accounts have been successfully run this way for years for the vast majority. Make it harder for people to get their money and you've created a significant friction point that will see your less tech-savvy clients almost literally flee to other banks.
The problem with this is that if that if there is a breach your typical bank will not take responsibility and claim that the customer is liable.
It needs to be written into law in all jurisdictions, that if a bank has been negligent in security, then when responsibility for a breach is unclear the benefit of the doubt should be given to the customer and the breach classified as a bank robbery.