Great talk! Nice to see examples of security measures and what exploits they protect against.
I know that some software like nginx, php and openssh often end up being left at the same version as when the server was provisioned. How big of a security risk is this compared to those you highlighted?