The answer is easy, the devil is in the details
Take away all control of the OS and locking of Android phones from the telcos and phone manufacturers as they have ALL done a crappy job with security and updates.
Put the onus back on Google. Maybe they should buy Cyanogen.
Make them split Android out as a separate, not for profit entity whose sole responsibility is to provide Android to the manufacturers in the various flavors and DIRECTLY AND AUTOMATICALLY UPDATE all Android operating systems for all devices for 10 years after the sale.