Because in most enterprise environments it's a welcome property to keep security updates separate from feature updates, which is not something rolling distro's provide, as they just follow upstream as fast as possible.
Say my enterprise application is built upon the API (in an abstract sense, if you will) of package xyz, version 1.0. And then xyz, version 2.0 comes out.
I would have to rebuild my enterprise application to be compatible with API 2 and I don't have the resources nor the incentive for that because I don't need API 2. Then a vulnerability gets reported in both xyz version 1.0 and 2.0 but xyz's maintainers only patch 2.0 (as 2.0.1).
In that case I am very happy that non-rolling (enterprisey) distro's like Ubuntu, CentOS, Redhat etc backport that security patch so I can keep running xyz version 1 (or rather 1.0.0-1 or something like that). Where most rolling distro's would just 'force' you to upgrade to 2.0.1.
Hope my explanation makes sense.