If you do it right, you get all the core components without incompatibulities.
But you will have to do more by hand and yes, then there is also a chance that you mess up those patches and create new vulnerabilities. But if you have a big budget ... like if you are a big military and security really matters, than it is probably worth it.
Better would be both. You have a strong, open base, like Linux, but you modify it, so you habe a second level of defence.