@MacuserJim is right. You can ask support to "pin" a device to a specific version if you have an issue.
I would personally just scheduled in the updates when you can arrange the downtime. Not patching devices in this day and age of security threats is not an option (IMHO). The vast majority of sucessfull exploits use existing known and already patched vulnerabilities - and companies simply have failed to deploy those security updates.