While you can't make software perfectly secure you can make security updates as easy as possible. Drupal is exceptionally bad at this.
IMHO Wordpress does the right thing with its auto updates. That still doesn't solve the problem for plugins, but it's probably prevented a lot of hacked sites. I think a CMS without an autoupdate functionality cannot be recommended for general use these days.