To each their own I guess. I would call this the "what you don't know can't hurt you" approach. What would this threat and risk analysis be based on? Known threats? Unknown threats? How can you quantify "proper"?
In my opinion, if the threat could actually be defined, then there would be no security industry. Everyone would know the answer, and everyone would be secure. The reason this industry exists is because you cannot define the threat, it is constantly evolving. Doing nothing because it does not matter (really?), or justifying a lack of security by lowering the value of the customer's data sounds like an unprofessional approach.