WP community has been updating WP version and releasing security updates frequently so we need to keep our sites updated always. I usually do it for client in every 3-4 months.
- Take a full backup of the site including database and images
- Update everything including PHP version, WP version, themes, plugins etc
- Check any issue or vulnerabilities
- Fix any issue if there is.
- Make simple / easy changes