First off, it would take two or more system updates to do it safely. First update they have to update NATIVE_FIRM give arm9 new functions for writing to that region of NAND and verifying it. Then actually creating the secret sector. Since Arm9Loader isn't installed yet, having secret sector present at this stage has no impact on the system as it's not used.
Then the second update will update Native_Firm to the new Arm9Loader version of it and the FIRM partitions would be updated accordingly.
If they can't create secret sector in the same go in the first update, then they'd do it in a second update and move off the Arm9Loader install to the third update.
In theory that would work. but Nintendo seems reluctant to do it.