It sounds like a reverse lottery of pain to me. If LulzSec looks at you, you get to spend millions beefing up security while your competitors do nothing.
They can choose when and where to attack, but you have to defend everywhere all the time. I suspect we're in a situation where cost of being competent > probability of lulz * cost of remediation.
...or, you know, be competent in the first place.