How do you know that IT pros are less likely to implement a workaround than hackers are to exploit it?
How prevalent is deploying workarounds and mitigations versus deploying patches? I don't know of any research in this area; it would be very interesting to know.