I am not surprised you are confused. First, let me start by telling you that I am not a follower of the mainstream. I was for decades, but have since changed. Most of the other advisers in this forum and most of my colleagues will disagree with me, some vehemently.
I would appreciate your reading my Profile which you can find by clicking on the CT icon. I am a very knowledgeable expert with over 50 years of experience in the field. I have been a contributor to thousands of questions in this forum for 10 years now.
I look after 120 windows 7 client machines and have for many years. I was one of those people who believed the sky would fall if I did not apply updates regularly. About 5 years ago, Microsoft started using WU (Windows Update) for much more than what it had been for a few decades -- a security system.
At that same time (which coincides with the end of Windows 7 development), Microsoft fired its entire Quality Control staff that looked after WU's. Ever since then WU has become almost a comedy of errors. Actually bricking millions of machines. A related fact is that Windows 10 by design allows no choice on WU. It just does it when it dam well feels like it.
At the beginning of 2015, Microsoft started using WU to push "updates" that would force its customers computers to become more useful to Microsoft. Many, including me, resisted that because Windows 7's design allows you to decide what updates to use and when. Then about 4 years ago, Microsoft changed the structure of WU's such that you in effect had little choice but take them all or none. They called those WU's "roll-ups" That is when I started thinking, do I really need this and is it worth it. I am not alone, Woody Leonhard is a world famous Windows Update expert and has a very popular blog. He wrote about this. He called the patchacopolipse. You can read his blog at https://www.askwoody.com/
In October, 2016, I started using "security only" updates that were available on Microsoft servers to those who knew how to use them. Then in June, 2017, they made a very unfortunate change. The corrected an error in a Security only patch that was only correctable by using their "roll-up" updates. That is when I stopped all Microsoft updates.
I concluded that the risk of Microsoft turning my smoothly running Windows 7 machine into something that I would not ever consider purchasing was greater than the risk I would be taking by not applying updates.
At this point, my 120 client Win7 machines have not had an update in 31 months. That well over 3000 machine months. There has not been a single instance of a problem. Not one. In fact they run beautifully day in day out. I used to average about 6 client calls a day. Today, my phone seldom rings at all.
My client machines use Chrome exclusively and a top-end ANTI-Virus product. Note well, that this product is not a so-called security product. It is an Anti-virus only product. I am not allowed in this forum to name a product.
I also must point out that none of my clients are enterprises and I would never suggest my strategy for such an environment.
Chrome does not need Java, Adobe Reader, or Adobe Flash Player -- three of the most security problem prone applications on most computers. i have uninstalled them.
I have a very detailed process I follow to do this work. You can read my posting on Woody's blog at:
https://www.askwoody.com/2019/canadian-tech-how-to-rebuild-a-win7-system-with-minimal-snooping/