When should a security patch be released?

Once a vulnerability is found, deciding when to publish the patch is genuinely hard. Rush and the patch ships without adequate verification; delay and the exposure window grows.
This work represents the vulnerability discovery process as a non-homogeneous Poisson process, because discoveries do not arrive at a constant rate — they cluster shortly after release and change over time.
On that basis it defines a total cost combining the loss from attacks with the cost of developing and verifying the patch, and derives the release timing that minimises it.
The result shows mathematically that earlier is not always better. It provides a basis for deciding security response by calculation rather than by instinct.
Source paper
Optimal security patch release timing under non-homogeneous vulnerability-discovery processes
ISSRE (International Symposium on Software Reliability Engineering) (2009)