Now the world evolved to the point that patches shamelessly remove features or install adware. Even the big names are incompetent enough to cause damage on a regular base. Meanwhile, the internet learned to deal with botnets as a fact of living.
So, assuming you live in a country where identity theft isn't much of a problem, and assuming regular and working backups are implemented, I start to wonder if it isn't time to review our best practices: Don't allow anything on the internet unless it really should (get a good enough firewall), don't run as root or administrator unless you have to, but also disable automatic updates, and do manual updates when a patch is out for 2 weeks and has proven not to cause more trouble than good.
So what's your opinion? How should a non-techy deal with today's landscape?