a) significant down time b) potential loss/corruption of the existing database
Maybe benefit of a timely update would outweigh cost of prolonged (e.g. a day) downtime and a database reset, as the instance if currently inactive and amount of content is currently small.
Obviously, it does not mean further updates should be disruptive.
Maybe this is the problem? Should there be more than one admin?