It’s always effort vs risk.
Since it’s a do once and forget kind of thing I’d rate effort rather low.
As for risk in the worst case scenario a single service being compromised means all of them are with the attacker getting access to everything those services can access, including all the credentials. Will you make an effort to be on top of all the updates for all services?
As far as I’m concerned: At home all containers for each service get a separate user. At work every container does.
Daily fine will only work if it’s increasing. I’d start him at a million euro per day and double it every 7 days (it would take just over 2 months to reach 1B/day)