I think that what you find in most industries are overworked admins with little to no time to deal with crucial security issues. I have worked in places where they are global and have staff needing support at all hours in all timezones. It is nearly impossible to update 80+ servers, without causing downtime, which as we all no is inexcusable
I am just taking about critical security updates, I must admit that no we did not test the updates they were deployed as fast as possible to both *nix and windows boxes. Was I lazy absolutely not, just dealing with unfair expectations of no downtime. Yes there are lazy admins out there, but I think for the most part they are trying no to upset the apple cart, it doesn't make it right but...