> The predictable second step after the bleeding stops is to do a line-by-line audit of their entire code base.
And this would be unnecessary if a vulnerability was discovered internally rather than demonstrated to exist by a well-meaning outsider? (Never-mind a malicious third-party).
A bank that left the back door open wouldn't need to conduct an audit if the breeze was noticed a few years later by a teller, rather than if it was pointed out by a customer throwing notes on paper aeroplanes through the open door?
(Ditto all your other points).
You cannot and should not assume that a "0 day" (questionable terminology in this case) has not already been discovered and exploited.
And this would be unnecessary if a vulnerability was discovered internally rather than demonstrated to exist by a well-meaning outsider? (Never-mind a malicious third-party).
A bank that left the back door open wouldn't need to conduct an audit if the breeze was noticed a few years later by a teller, rather than if it was pointed out by a customer throwing notes on paper aeroplanes through the open door?
(Ditto all your other points).
You cannot and should not assume that a "0 day" (questionable terminology in this case) has not already been discovered and exploited.