So if you rebuild your docker containers every time you deploy, and you deploy daily, security updates should happen on a daily basis. Correct?
And if you have a continuous integration environment building and validating artifacts on every developer commit with a regular, vetted release cycle that catches any regression bugs...
Well, now you're on the right track.