OP Here. Don't forget the great majority of data breaches are due to very basic issues i.e. unsecure passwords, shared credentials, unsecure API endpoints, etc. When hackers try to find their target, unless very specific cases, they start with the easiest path. This is where you have a word to say.
They may come for you, but with the right settings, it might not be worth the hassle.