Too soon your site can break, too late and your site can fall victim to an exploit. Have to find a sweet spot in between. Usually, you will get exploit notices in an email from wordfence (if you signed up), they make a big difference.
I have most things set to auto-update, But with that said, I have had updates that broke my website in the past which needed to go into debug mode to fix. WordPress is kind enough to let you know what plugin threw the critical error most of the time too.
None of these have ever been compatibility issues though, Usually mistakes on a devs part which they pushed a fix for before I even noticed it happened. WordPress also does its best to show pages and content even if the backend portion is broken. CDN with a longer expiration time also gives more protection to that sort of downtime. So a bit of redundancy there, but you can't count on it 100% of the time.