Instead of having a single big kick ass dedicated server running everything, you can have maybe 10 VPS's each doing a different thing. You can group things together in terms of risk - put wordpress on its own vps, put your customer db on another, etc etc. At least then, if someone hacks into wordpress, it doesn't really matter that much - they only get wordpress, nothing else, and you just clean off that machine from backups.
(Obviously have completely different login credentials for each VPS, and only grant access from one VPS to another when really necessary, and restrict it).
But yes, you are right for the most part. However, just throwing apps in VPS doesn't automatically solve your security issues.
Yes, there could theoretically be a way to punch through from an insecure VPS into a secure VPS on the same host, but I think the chances are pretty slim there.
The security is just an added bonus.