It's easy to forget about updates. It's comforting to get a system to a stable state, where no matter how much it's hammered, it's going to continue to chug along, doing what you've told it to do, and nothing more. What's uncomfortable is the idea of breaking that perfect peace, and that's where updates come in.
Software doesn't stand still; there are features being developed, security holes being patched, and tougher encryption methods being implemented, and all of these need to be accounted for by you, the sysadmin.
Package maintainers can do a lot, and they do, but it's up to you to make sure that what you're updating is tested, that it won't break anything else in your environment, and that those developers that were using an exploit to get their code to work on your...