Suphp is outdated, and even the original developer has stated the need for it is no longer. Php-fpm event, in kloxoMR runs under your client name, directory restrictions in place, and just blows suphp away in performance.
Mod_security is great, if you know what you are doing, as in being a knowledgable server admin. Hiawatha web server is a neat little webserver, SECURE, able to protect against a lot of attacks, and well, my preference. I left apache when one of our production servers was running constantly at 8.5 load due to apache. Hiawatha, same server, about 4 - sometimes slightly more, but just a drastic difference under load/high traffic.
I know the die hard apache fans will start barking about settings/configs/whatever... well, hiawatha does it faster, easier, and WAY LESS RAM.