Yeah, it's definitely a balancing act of security vs. reliability when it comes to installing iOS updates on iPads used for ST (or any key piece of band/performance tech).
Worst case, this is where Apple's very slow iOS auto-install process works in your favour. I like to wait at least a few weeks after a release before I install. And I also need to advise bandmates as having a mix of iOS version Clients connecting to the ST Host is also undesirable.
The other rule I stick by is to only use the ST3 Host iPad for it's base function - running ST. It has no other apps installed other than what I need to facilitate my workflow to get audio and lyric files onto it. Definitely no web browsing, no email (which does present a problem if needing to collect logs for support as ST simplifies the process by creating a support email in the default client with the logs 🙁 Would be good to allow logs to simply be exported somewhere.), etc. Uninstall any default Apple apps that aren't needed.