Can't you configure Active Directory to push all the patches without actually having to use SUS (Group Policies)? Also, for non-MS updates, I would look at some kind of scripting option...

Cheers,
cgkanchi