This is something that has always bothered me. I've worked in software for awhile now, but never in the financial sector, yet the vast majority of my clients and employers have had third party security audits run on their code and systems. I don't know why every exchange doesn't do this and talk about it publicly.
Everyone in the biz or following the biz knows its window dressing and pay to play. See Arthur Anderson and Enron and about a zillion other scandals over the years.