Applying the security update took minutes, even on a large number of hosts, thanks to automation.
The harder part was working out how to treat things from there, did we need to assume we'd been hit in the past, and regenerate certificates? That took a good couple of hours of debate with different people.
Call it half a day to be generous.