Operating systems are ever changing, just because they're new doesn't mean they're better.

We've seen too many times early adopters syndrome only for the latest and greatest os to introduce a large number of attack vectors. Every change or modification comes with risks ... evaluating risks is what we do.

We can enumerate risks so tradeoffs of time vs money can be evaluated and risks mitigated. Risk can never be eliminated. This is why risk enumeration is one of the first steps in understanding the path an organization will need to take.

Why risk assesment ? It's the only way to understand what's at stake.