The manpower necessary is not enormous. Any particular security update has a relatively small chance of requiring prompt installation on a particular production service. On the unusual day you're struck by lightning, you pull out the relevant emergency plan and begin executing it.
In such a situation it's probably safer to at least have automatic scheduled patching against deadly vulnerabilities and accept that occasionally that might break something.
Of course that wouldn't apply in apple's case.
If you want to completely mismanage a server you depend on for your livelihood, I can't stop you. All I can say is you're doing it wrong.
There are a lot of poorly managed VPS out there, these would be better served applying security fixes automatically.
Given that, your question of "how can we completely avoid zero-day attacks" is nonsensical.