VPN is not a basic security feature. VPN by design is not supposed to provide security. It's marketing. When BlackBerry died, the reins on security issues were taken over by Apple. It can be debatable, but currently there is nothing more sensible.
The person to whom you are responding understand how old phones work and why they are dangerous. You probably left out all the other indicators.
Yes, I use the first-generation iPhone SE, which still gets updates.
Unless you consider the topics of 'privacy' and 'security' to be distinct for semantic correctness, I don't know what you mean. VPN is not supposed to provide security??