Pretty hard to own a VPS which has no external ports open, even if the software on it is years out of date. In fact, updating software is probably a bigger security risk than not doing so, because you never know when someone manages to package a malicious bit of code into a common debian package.
Also, if it did get owned, I'd just have to spend a few hours rebuilding it - no bitcoin wallets or anything to steal on there.