Security is something you have to be aware. The easiest way is to just setup the server with https so that the communication is secure. This seems to be the recommended approach for client server communication that Google them self suggested during the Google I/O app security session.
We currently don't use Switchboard for anything where you can manipulate the behavior of the app. Remember, the code that gets executed is still in your control when you build and sign the binary.
We focus a lot on streamlining the development process. We're only two people cranking out code all day. For this reason we want to have one version out there that we're able to maintain. We test the app that it runs on as many devices as possible and crashes as little as possible. The problem with providing old versions is that users then also have support request about old versions. At this point we're getting about 400 emails a day. When a user has an old version, we send him an auto reply to update to the latest before we deal with the problem. Otherwise it's not getting manageable.
I think Internet access is by now default for close to every app. You can always justify it in the app description with Ads, even if you never show a single ad in the app. Another option is to track crashes. Here the same again as before, if a user does not like that the app needs internet access, he should just download a different one. The reason here is that you will not be able to improve your app ongoing if you can't measure what happens.
Linking the analytics together with tests or stage roll outs back to an automated configuration tool is super cool. But again, we're 2 people and we have a pretty good overview of what we're running and what to look at. But I agree that this becomes very powerful when your team size gets bigger and not every engineer is keeping track of all business metrics.