People go on and on about backported security patches and stability, but I’ve had to handle so many buggy patches or issues that never got a backported fix that I now think this is basically a fantasy. The distro maintainers just don’t have the time (or experience with all the software they ship!) to backport patches for every single issue. I’d really rather get a fix by the actual software maintainer than a year-old mystery meat version that still has a bunch of known non security bugs fixed in upstream that the distro maintainers don’t care about.
Even worse, being able to stay on essentially outdated software puts a lot of organizations into a tough spot when their LTS version finally becomes unsupported. Practice makes perfect, and I think lots of small, regular updates result in a lot less pain than a mega-update every few years (really: I’ve had to manage one of these more than once, and it’s a total nightmare figuring out which of 1000 changes in the new LTS version caused a performance regression or something).