Which industry!? Why two months for something that is this critical?
Let me explain this part!

Microsoft industry-standards {Has been used interchangeably in the article}:

[1] Late vulnerability reporting.
[2] Late vulnerability patching.
[3] Late vulnerability exposing.
[4] No patches for petential risks, only for proof-of-concept and exploited vulnerabilities.
[5] Giving enough time for Spammers to fool people, since MS always helps people.

As I said, MS always gives enough time for Spammers and black hats to exploite and earn some money before they patch, MS always thinks of other people.

Hope I could explain, even a little...

Cheers