My laptop is about 10 years old, but I asked a guy from Microsoft about upgrading and he advised me not to bother and recommended getting a new laptop.
You can try installing windows 10, if it has no SSD which I suspect it wont, install one, even a 120GB SATA SSD is cheap a 120GB one in Australia is $40 which would be around £20, £30 might get you a 240GB one.
I connect to work via the work's VPN, but a VPN doesn't provide you with any better protection against viruses etc., does it?
Nope.
A VPN can still get you infected.
Go to a site that you know has malware and boom, you're infected.
Download a infected torrented movie and boom, you're infected.
One thing I don't quite get is, how vulnerable to viruses would my computer be if I keep it online but only to ever use it for remote connection i.e. no web browsing? I'm assuming that the computer will still be vulnerable to viruses/attack just by virtue of being connected to the internet, and that connecting to work via a VPN will not make the computer any safer...
Remote attacks due to bugs in the OS which can be exploited.
Many types of malware will try to ping random IP addresses and try to infect PCs that are not patched.
Wannacry exploited a bug and then spread via networked(Local or Wide) computers by exploiting the same bug.
Oddly enough microsoft released a patch for this months before wannacry hit
If you use safe browsing habits and common sense.
You can reduce change of infections down to a near 0%.
Do not illegally download things from torrents
Do not click on random links
Do not use flash
Do not insert random flash drives into the PC.
Keep programs up to date.
You could try and run a VM and do the work though it on your laptop.
If the VM gets infected.
Just replace the image with a backup.
Heck it is what I do with those "Microsoft Call center" guys.
I run an old XP image in a VM, let them mess with it, infect it.
Then I restore the image to before I let them in.
Besides most common form of malware today is "Ransomware" so as long as you keep backups and do not keep NAS devices constantly connected you should be fine.