If it’s the latter, I think the industry as a whole will do a better chance of defending itself. It’s when IT managers aren’t worried about something — like the flaw in a piece of software, or the way certain users behave with their devices and data — that a breach of some kind tends to occur.
A few months ago, meanwhile, Mari-Len did a more in-depth feature for ComputerWorld Canada on zero-day attacks and how to handle them. It’s worth a second read.