McAfee: Businesses 'leery' of Vista

McAfee: Businesses 'leery' of Vista

Summary: The security vendor has said companies are reluctant to move to Vista as the security case doesn't justify the hardware upgrade, while analysts say most will move only when Microsoft ceases XP support

TOPICS: Security

Vista uptake is unlikely to increase dramatically during 2008, according to security vendor McAfee, who said that businesses are "leery" of upgrading from current Microsoft operating systems.

One reason businesses have not been keen to upgrade to Vista is the hardware that is needed to handle the resource-hungry operating system, David Marcus, security research manager for McAfee Avert Labs, told on Friday.

"In 2007 there has been less than 10 percent market penetration for Vista," said Marcus. "There hasn't been a huge adoption. Most people haven't upgraded because of the hardware upgrade needed."

There is not enough of a security case for upgrading to Vista, Marcus added. While the 64-bit version of Vista has more security features than Windows XP, XP running Service Pack 2 with security products was adequate for most businesses needs, he said.

"XP is still robust, and is sound with SP2. Most businesses are looking at it from the point of view of, 'Why change out for some nice graphics when XP does what we need?'," Marcus said. "People are leery of upgrading."

There was, however, a security bonus, Marcus said. Vista would be unlikely to become an interesting target for malware writers until it achieved 20 to 30 percent market share — a figure that is still some way off.

"Once Vista gets the numbers it'll become interesting to the bad guys, who'll find ways to circumvent it like anything," said Marcus.

Vista 64-bit security features, such as Kernel Patch Protection, which blocks attempts to modify the core operating system, would not be effective against certain types of malware, Marcus warned.

"If you look at Trojans and bots, the majority just sit on the machine and do what they do — they don't have to root the operating system," said Marcus. Social engineering attacks that attempt to dupe the user will also continue to be a problem on Vista, he warned.

Vista Upgrade Blog

Vista Upgrade Blog

Grappling with the OS

How is the switch to Vista affecting your workplace? Take a look at our new group blog and share your pain and praise.

Read more

Forrester research suggests that most businesses are keen to stay with XP until at least 2010. In a report, How Windows Vista will shake up the state of the enterprise operating system, Forrester analyst Benjamin Gray wrote that while Vista uptake is currently at two percent, XP is at 84 percent.

"There it is. Two percent! The era of Windows Vista within enterprises has officially started, with a whimper," wrote Gray. "Standardisation on the Windows XP platform has continued unabated, going from 67 percent of PCs last year to 84 percent of PCs this year. And this happened across the board."

Gray said that the majority of businesses will move to Vista only when forced to, by Microsoft ceasing to support XP. The current road map for XP Professional states that extended support will end in April 2014.

"For [mainstream adopters], the justification [to move to Vista] is simply that they want to stay current with Microsoft's support lifecycle," wrote Gray. "Many will move to Windows Vista simply because they don't want to go down the path of supporting a system that doesn't receive security patches on a regular basis."

Just over half of enterprises have no current plans to deploy Windows Vista, according to the research.

Microsoft had not responded to a request for comment at the time of writing.

Topic: Security

Tom Espiner

About Tom Espiner

Tom is a technology reporter for He covers the security beat, writing about everything from hacking and cybercrime to threats and mitigation. He also focuses on open source and emerging technologies, all the while trying to cut through greenwash.

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.


Log in or register to join the discussion
  • XP security support will continue until 2014

    I'm not sure where people are getting the idea that security support for XP will end shortly. Here's the official policy, from

    "Microsoft will also provide Extended Support for the 5 years following Mainstream support or for 2 years after the second successor product (N+2) is released, whichever is longer."

    Extended support follows mainstream support and does not include hotfixes and service packs, but it does include security updates, paid support incidents and, if you sign an extended hotfix agreement, which a lot of large customers do, pretty well any kind of support you'd like, including hotfixes.

    According to the MS lifecycle, XP will be in mainstream support until April 2009 (probably within a year of the release of Vista's successor), and in Extended Support, WITH security updates, until April 2014. That's assuming that the replacement for Vista (the N+2 version of Windows) is released before 2012. If they take longer, XP support will last longer.

    See for the dates.

    Al cook
    Al S Cook-4ec56
  • Yes, Microsoft will support XP until 2014

    Thank you for taking the time to post a talkback, Al. Your comments on the Microsoft Support Lifecycle are helpful, and go into good depth.

    However, you seem to be under the impression that we didn't include that Microsoft plans to support XP until 2014.

    From the article:

    "The current road map for XP Professional states that extended support will end in April 2014."

    Best wishes,

    Tom Espiner