The problem I've had with Forge is that although it sets up the server perfectly, unless I'm mistaken it doesn't seem to do any sort of Operating/Package or system/security updates (or alert you to those that need doing?)
Probably not the right place for this however just looking for some clarification from a forge user @FWSimon ?