We simply weighed the risk of the vulnerability (very slight) against the business risk of a broken mail server (holy shit) and made a decision accordingly.

I'd do the same with any box, running any product on any operating system - applying patches the *instant* they appear is never wise, and is only rarely necessary.