I thought most attacks these days were on clients (especially mail and web clients), not
servers?
But that would at least address the "how do you get security updates on first boot"
problem--just get them installed before starting the web browser....