In general, the time to fix an identified security hole is dwarfed by the time to investigate a breech.
You have to identify the actions taken by the attacker and correlate events between systems to understand the extent of stolen, destroyed, or modified information, and to ensure that no additional backdoors are left behind.
If there is an indication of malicious intent, you also have to interact with law enforcement, discover the identity of the attacker, provide enough information to get a warrant, and so forth.
In the whitehat report case, it is as simple as fixing the security hole (and identifying how it got there and how to prevent similar cases) and thanking and rewarding the reporter. However, that wasn't the case here - there was no disclosure, no reason to believe that the attacker was benign, and so an investigation needed to be done.
(I work at Facebook, but not in one of the teams involved in this investigation.)
You have to identify the actions taken by the attacker and correlate events between systems to understand the extent of stolen, destroyed, or modified information, and to ensure that no additional backdoors are left behind.
If there is an indication of malicious intent, you also have to interact with law enforcement, discover the identity of the attacker, provide enough information to get a warrant, and so forth.
In the whitehat report case, it is as simple as fixing the security hole (and identifying how it got there and how to prevent similar cases) and thanking and rewarding the reporter. However, that wasn't the case here - there was no disclosure, no reason to believe that the attacker was benign, and so an investigation needed to be done.
(I work at Facebook, but not in one of the teams involved in this investigation.)