> But nethertheless, I intend to benefit too from an occasional automated security survey because I am sure I can find an attacker smarter than me.
For the people who proactively install, run and heed the reports from such tools there is no problem. It's the people who won't install it, won't run it or won't read the reports that you can't do anything about. For them prevention is out the window, recovery afterwards is all you can strive for.