You can't imply that it's the sole customers' fault by saying that it's "the easiest thing to do - update operating system" without mentioning NSA not cooperating with Microsoft to patch the hole.
Many setups require certification which is void after modifications which may include system updates so it's not "the easiest thing to do". It needs to go through the certification process again.
Even without certification requirements it may not be as trivial as it looks at first to "just update OS" on every device.
The "easiest thing to do" is for the government to report holes just like everybody else does.
Isn't it kind of strange that the only ones that fail to report security issues are a) criminals and b) government?