Because patching requires a quick risk calculation. Should I patch to the bleeding edge and get the latests security but risk a regression bug, or do I wait a bit so I can run a full regression test?
On my machines, sure I like to stay on the latest and greatest. But I'm sure there are plenty of companies that got bitten because some critical software they rely on didn't play well with the latest OS upgrade. Blame game notwithstanding, it comes down to a business disruption risk.
Of course, the right answer is to test the patches as they come out in a non-production environment, and go from there based on results. But I can see where some companies wouldn't have the resources devoted to do that on a frequent basis, which is unfortunate.