Since the publication of the first edition of this book, Canonical has released a new Livepatch service for Ubuntu, which allows it to receive updates and have them applied without rebooting. This is a game changer, as it takes care of keeping your running systems patched, without you having to do anything, not even reboot. This is a massive benefit to security as it gives you the benefits of the latest security patches without the inconvenience of scheduling a restart of your servers right away.
However, the service is not free or included with Ubuntu by default. You can, however, install the Livepatch service on three of your servers without paying, so it's still something you may want to consider. In my case, I simply have this applied to the three most critical servers under my jurisdiction, and the...