Hi Richard, I agree with the learning curve. The key (for me, at least) was understanding the difference between a static page and a dynamic post. One looks just like a regular website page, and the other looks (and acts) like a blog. Once you're in the editor, they both pretty much look the same. Let me know if you're having trouble with anything in particular, I might be able to help.
The past security issues were with -- is it called turnkey?? WP installations, e.g. on sites like GoDaddy. The ones where you'll see "one-click install" and things of that nature. If you use a regular hosting set up, or better yet a dedicated WP hosting site, they're quite secure so long as you keep up with updates etc.