Having a cooldown is different from never updating. I don’t think waiting a few days is a bad security practice in any environment, node or otherwise.
But only if most of everyone else doesn't do so.
But only if most of everyone else doesn't do so.