This forum needs a

syduck: emoticon.
Do tell me more in detail about this 'Windows stuff' please. I am all ears.
What web server software are you running? Willing to bet that its been problem free for the last 3 years?
You can update packages all you want, your kernel does *not* get updated unless you reboot or ksplice it live, period. Your packages do but as SunnyD already mentioned, that's only a partial win in some cases. The Linux kernel has had at least
455 public CVEs posted since you last rebooted your server. While true a RCE vuln via the kernel alone is rare, there is so much attack surface in your scenario it's mind boggling. If you think that running the latest packages alone is enough to stop someone from exploiting a known, vulnerable kernel once inside you've got bigger problems than thinking anyone gives a dusty fuck about your uptime. All that means is it's an easier target to pick off. This isn't 1996.
Anyway, keep doing what you're doing, you're ensuring a lifetime of ample, high paying work for people.