I've got folks using xp, who won't adopt sp1 ! Never mind sp2 ..

Personally I'm of the 'update it always immediately' line of thought .. but being confus-ed & all, this also means, I can (when the fancy takes me) switch tack, & say that firms who've done sufficient testing & have adequate 'insulation' from the outside world, might well be better if they have really complex systems, sitting tight on updates until they can estimate the effect of any changes on their greater system ...

(but for folks at home, this is not generally a good idea, unless you have a security expert & a big fat team of system admins to make sure no 'strangeness' is affecting any particular system - lots of 'really big firms' have policy regarding this, which is to the effect of 'test it first' )