You can get auto-updates and we do a pretty good job of protecting WP sites. But the situation is dire. A survey we did recently showed that 38.9% of respondents (out of over 7000 WP site admins) were hacked within the past 12 months.
https://www.wordfence.com/learn/2015-wordpress-security-surv...