No need for that. It's the provider's job to make sure his damn nodes are secure. Here's my low end upgrade strategy:
1. only upgrade when a major version comes out: WordPress 2, WordPress 3, WordPress 4, etc.
2. if I get hacked, I file a chargeback and start a thread on WHT saying it wasn't...