While I do not host OwnCloud, I do selfhost a significant amount of other services and strongly believe it can offer a lot of value in certain areas (or stages of business/work). However, part of what I think makes it viable in the current era is how good VPN options like WireGuard and Nebula are, along with various solid open source firewall/gateway options (VyOS, OPNsense, roll with OpenBSD etc). I can't imagine actually exposing anything I selfhost on the open internet, the surface area and lack of security practices is scary and has been for ages. At least separate VLANs for everything and access only via VPN from external, or at all for that matter (internal VPN or hard wire required for any access whatsoever to management interfaces, sensitive equipment etc whether internal or not, no trusting local clients by default).
Doing that itself certainly isn't perfect, obviously if facing actual targeted APTs horizontal movement efforts can be expected. But running a service with any kind of public exposure is pretty different in terms of threat profile and the sheer volume of attacks one can expect. Even with something really simple, some minimal static page serving, I'd still want it somewhere completely on a different network from my main stuff. Let alone huge gigantic complex many moving part apps like these cloud options! Individuals or small teams need to manage their available time/resources pretty tightly, and even a huge team would have trouble locking down something like that.