An open letter to the Open Source community (and the world I suppose) explaining the flaw in the report by Forrester Group titled, “Is Linux more secure than Windows?” It seems to give open and honest insight into the process that was taken to create the report and how the results are being measured. It is hard to expect any report of this nature to treat Linux and Windows equially and therefore most of these reports become useless. In the end security rests on the hands of the administrator. No good releasing a patch if it is not applied by the man in charge.

Significant efforts have been put in not only making sure that the underlying dataset for the Linux vulnerabilities was correct, but also to articulate the special technical and organisational care taken in the response processes in the professional Open Source security field. This expertise is greatly appreciated by our usership since it adds a high value to our products, but we see that most of this value has been ignored in the methods used for the analysis of the vulnerability data, leading to erroneous conclusions.