The best option would be to have a replica on vmware from your server, to load the patches on, to see what happens.
If one blows up the cognos part, you will have a culprit.
So i asume the consultant meant autoupdate is bad, but manual test/install after the update is a few weeks old is safer/best practice.
Cognos receives the updates proably the same time as you do. That does not give them much time to test, find, repeat, fix and release a hotfix for an issue. Cognos supports every issue you will have with MS hotfixes, but with all that downtime, you will not be happy.