Thank God We Use SQL Server (Not Oracle)
I found a recent news in Dark Reading, "10 Oracle Bugs in 10 Minutes". It's about a researcher who found nearly a security bug a minute in Oracle 10g R2 during an audit demonstration of the database software in Black Hat DC. He used free software that can be downloaded by anyone.
The same site also reported that SQL Server is the safest database. Also read this Oracle vs Microsoft database security comparison from NGSSoftware.
So the next time your client ask why you choose to use SQL Server and not Oracle, tell them that it's simply the safest, and more secure than Oracle. 