Well at a minimum off site backups should be considered. Even better are off GRID/NET backups. We do backups here of our own site and store those backups on DVDs. Even our own business computers with designs, graphics, contracts, emails and tax info - a copy is stored at my location (Nebraska) and a copy is stored at my business partners location (California). This was also necessary in order to follow our business plan and life insurance so that if one person did die, the other could continue to operate the business.
There's a number of FTP programs out there that can schedule backups for you. I believe CuteFTP has a setting that it will log into a folder and you can download "X" on a schedule. You could easily have the database dump to a file, then download that file via FTP on a regular basis.
Granted, data such as the emails etc would be a concern, but if they're going to hack and take your data, and you've already secured things as best that could be done, then that's about all you can do. Have a backup on hand, contact the users so they know whats going on, and then move forward.
I think contact is a big concern. I haven't received anything from WHT to say that their site was compromised. I KNEW it was, because I couldn't get on, but if I hadn't been checking, would I ever have known? Communication is key in every busienss, and an online forum is a business like it or not!
VPS and Dedicated Servers are pretty much the same when it comes to the security level. The only two things shared are the Kernel and the Memory for the most part.
As long as your security checks are in place, and you're making regular backups, thats about all that anyone can ask for.