At a past job I had to provide detailed arguments for why we needed to update to this or that security update of critical software.
All because *once* there was a bug in a patch release (that was fixed within an hour) and the CTO was forever weary of updates.
Don't be that CTO.
I've seen people justify slow security product updates with "maybe we'll skip a bad update."
No you will be down for 26 hours because you didn't get the immediate correction the vendor issued. We update antivirus hourly. AV HTTP checks are smaller than a JPEG on Bing.



