I have a simple principle in this matter. I trust the makers of an OS to know what they are doing. Whether Windows, a Linux distro or Mac, I let them install any updates automatically when possible. In Windows for instance, most updates are because Microsoft has found a vulnerability or a bug and releases an update to patch that. I feel not updating would be irresponsible behavior from me, not taking care of my property, my computer.
Maybe not a good metaphor but anyway, think this: You install a well known, working AV application with todays virus and malware definitions. Should you then leave it as it was when installed, no longer update definitions, trusting that the old virus definitions can take care of the future viruses, too? Windows Update works according to this same principle; your Windows when installed was / is as safe and OK as was known to Microsoft when they released the version you installed. When new threats, vulnerabilities, bugs and so on are found, they are patched with an update.
Of course it's up to you to decide what to do with your computer. The above mentioned is only my personal opinion.
Kari