To answer your first question, shutting down the server is exactly that - a way to prevent data loss and corruption. As long as the server is off, the hackers can't do anything to it, because it's not powered on, presumably.
To answer your second question, I would say that would be upon the owners of the hosting company - it is not the responsibility of a customer of a hosting company to provide it's own security - that's one of the reasons subscribers pay for their services. Stability is expected.