Mature security teams for example use Bloodhound which uses neo4j to visualize attack paths in AD. Defenders (good ones) don't think in lists.
> "The defender’s job isn’t defense."
Yes, it is. Obviously!
> "It’s a side show, and a distraction from the main business of whatever else the defenders are trying to do"
I'm sorry, but what else are defenders trying to do that isn't defense? are all defenders completely incompetent then?
> "By contrast, an attacker’s entire job is to attack the system."
Yes, and there are people in mature security teams whose entire job is to search for and stop (not just react to alerts) attackers.
> "Attackers win for the same reason that Microsoft is better at publishing operating systems than Cisco, because ciscos operating systems are a means to an end. Microsoft’s are the end"
I think you have an incorrect perception of what security teams do. It is both a matter of strategy and resources. There are security teams whose budget is in the 100's of millions of dollars and who employ some of the brightest cybersecurity strategists and professionals. You rarely (if ever) hear their names in relation to a breach or compromise. There are also much less capable security teams who do well against most attackers, but will inevitably get pwned by an APT, except the good defenders catch the apt's before they cause significant damage.
At well protected organizations, attackers lose 99.9% of the time (probably higher, I'm guessing here). Attackers simply need to win once to succeed, while defenders need to succeed 100% of the time.