Quote somewhat taken out of context. The quote itself seems quite rude (and should have been worded differently). However, the gist of the article is correct -- that users should not be expected to fix security holes. IT must do it.
Lets not forget why our industry exists. We don't exist solely to entertain ourselves (that's just a fortunate side-effect
). We're here to serve those "foolish" users, and providing them a secure environment in which to do their job is part of our job
we've been pretty rotten at so far. Blaming them for the problem is an insult. However, recognizing that we (as an industry) must address a security weakness without relying on the users changing their behavior is a correct perception of reality.