This boils down to how vigilant and competent your IT people are. It doesn't matter whether it's on Linux or Windows. Remember Conficker ?
BIND is hardly installed on just any Linux system. If they are smart to install and configure BIND, trust me they are smart enough to upgrade it
just like if you are smart enough to install Windows server then you must be smart enough to patch it up to date.
Please we do not need extremist here




