It's clearly true: it's cheaper to prevent vulnerabilities than to find and exploit them.
If you consider "defense" as an organization attempting to provide a service securely, and "offense" as all the security threats they are exposed to, it seems hard to argue that the defensive side has any sort of advantage over all of the attackers.