The notification arrives at the worst possible time - mid-task, mid-call, just as you were about to do something else - and it asks to restart, or to wait while it installs, and so it gets postponed. Everyone does it, and the postponement quietly becomes permanent: a phone, a computer, an app running a version that is months out of date because the update was never quite convenient. This feels harmless, because the device works fine as it is. But a significant proportion of software updates are not about new features at all. They exist to fix a security flaw that has been discovered - and once a flaw is discovered and a fix is issued, the flaw is no longer a secret.
The uncomfortable logic of security updates is that publishing the fix also publishes the problem. When a maker releases an update that closes a hole, the existence of that hole becomes public knowledge, and people who make a living from breaking into systems now know exactly what to look for and where. Their target is not the up-to-date device, which is patched; it is the large population of devices whose owners have not yet installed the update. The window of danger opens, in a sense, at the moment the fix is released, and it stays open for each device until that device is updated. Postponing the update does not keep you at the old, quiet level of risk - it leaves you exposed to a hole that is now openly known.
This is why "it works fine, so why update" is the wrong test. A device with an unpatched security flaw works perfectly well right up until the flaw is used against it; the flaw is invisible in normal use, which is precisely what makes it dangerous. The same applies to the software that runs a small business - the systems, the plugins, the tools that quietly power the day. An out-of-date component is not a problem you can see in its behaviour; it is a known, documented weakness sitting in place, waiting, and the only signal that it mattered arrives after it has been exploited, which is too late to act on.
The sensible habit is to treat updates, especially security ones, as maintenance that is not optional rather than an interruption to be dismissed. Where automatic updates are offered, turning them on removes the decision entirely and is almost always the right choice for phones, computers and everyday apps. Where updates must be triggered by hand, the discipline is to install them reasonably promptly rather than letting them pile up, and to pay particular attention when an update is described as addressing a security issue. The moment of updating is a minor inconvenience; the thing it prevents is the quiet, invisible persistence of a weakness that someone, somewhere, already knows how to use.