You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.
Minimizes money usage and does not require any security investments
That's like blaming Seagate when your harddisk fails.
No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.
That sounds risky
Perhaps they should read https://en.wikipedia.org/wiki/Piercing_the_corporate_veil
Or … and hear me out on this one … care?