The Acquia blog post about this [1] is up-front with the fact that major companies who participate in the Drupal Security Team had a 7-day lead time on everyone else for this vulnerability. 7 days! Everyone else learned about it at the same time the bad guys did, and it turns out they had about 7 hours before attacks came flooding in. [2]
Particularly for folks in Europe, this was potentially disastrous, because the vulnerability and patch were released at about 10pm their time.
The Acquia blog post concludes by thanking the "all-volunteer Drupal Security Team." But the reward for participation is obvious: advance warning. If I ran a big Drupal shop, I would direct one of my engineers to spend time on, and try to join, the Drupal Security Team. It's just good insurance.
I am a Drupal user, and I have made sure that we are doing business with at least one of those companies, for the same reason. I was warned on Tuesday that a critical patch was coming on Wednesday; we were ready to go and patched everything within an hour of release.
Does that seem fair? I have to think that there is a better way to release these sorts of critical patches. I can't think of any reason the Security Team could not have posted a public announcement on Monday or Tuesday saying "get ready--critical patch coming Wednesday." Instead we got a PSA 2 weeks afterward, telling people that they should have been faster.