To soothe a little. Major companies get breached because they offer a better ROI for the baddies. I am not obligated to any entity to prove I am secure. I am obligated to myself. I use a top of the line physical firewall which I set to be very strict for my work machine. Likely, it is as good as any :commercial grade" firewall, as I actually set it tight. Monitored firewall is likely OK, but I would bet some amount they use the same settings for most of their clients (a default of sorts) to keep their support simple. I suspect what you are really paying for is someone else to be in the liability chain (if they were not smart enough to waiver out).
On the other hand, there is at least one locality who has legislated "security" (likely for their own political perceived gain) where data is required to be in the physical control of the person, and stored within the jurisdiction. No online backups for those folks, and in the real world, worse security.