In my experience a package's ability to cope with a complex uninstall scenario generally improves with the initial upgrade - or any upgrade for that matter - (for example, sometimes dist-upgrade-specific issues are only discovered by the maintainer as part of the coordination for a release) and so (in my experience) the reliability of the "dist-upgrade" is usually increased by doing an "upgrade" first. Dist-upgrade is one of those things that "should work" of it's own accord, but there are ways of increasing the odds; I have found a pre-"dist-upgrade" upgrade is one. (Sometimes I'm impatient and only upgrade apt/aptitude before a dist-upgrade though.)
I would say it makes more of a difference on systems that are infrequently upgraded in general since a few points away from the current versions aren't going to contain many differences anyways, but I'd certainly be more hesitant to dist-upgrade from a .0 release (6.0 to 7.x, for example). I'd almost rather clean-install in that scenario since it amounts to a similarly-sized download.
In my experience, there's value in doing a standard upgrade before a dist-upgrade. It seems to help to fully update the system doing "upgrade" before "doing the upgrade" (dist-upgrade) that will uninstall things... That said, it can obviously be a bit of a waste to upgrade everything like gnome just to uninstall it immediately... As such, I typically manually uninstall large tasks then upgrade then dist-upgrade and manually add the tasks back. In "theory" it should just be as you say - one big dist-upgrade - but I've yet to encounter an upgrade that didn't need special attention and I have learned that minimizing the installed base being upgraded is a good first step to a smooth transition.
Whenever someone uses "security" lately I start reeling...
"What do you even mean by security? Privacy? Transperancy? Anonymity? Accountability? Reliability? Physical safety? Harmful to bad people or helpful others, and how? What specific properties and, for that matter, from whom's perspective - your's or mine?"
The term "security" implies so many ideas and many of them contradict that today it seems used mostly to help people feel safe while they are being cheated...
To that end, I would posit that anything that runs on Windows should be considered backdoored anyways, so I can't imagine why I would trust it to help my own personal "security" (privacy, and physical safety).
I would say it makes more of a difference on systems that are infrequently upgraded in general since a few points away from the current versions aren't going to contain many differences anyways, but I'd certainly be more hesitant to dist-upgrade from a .0 release (6.0 to 7.x, for example). I'd almost rather clean-install in that scenario since it amounts to a similarly-sized download.