Or maybe large organization that have severe security vulnerabilities can at least inform the public when they should update in a timely manner.
It's the lowest hanging fruit. Can't trust an org to handle security properly, can't trust an auto updater.