IE7 is actually pretty stable now (a lot more stable than Firefox 2 that hung 2 times while I was replying to your post) and their added features are nice, however, if you have any applications that were created to run on IE6, then it is best not to update as these may not run at all.
I am sure that it is going to be another round of updates and patches.
If WIN XP and it;s software is a real ship, and given it's numerous patches and bugs, it would not pass MPA certification and are likely to sink with lives lost.
I think you should dump IE altogether and switch to Firefox if security is your main concern.
If you can afford 15mb.. I'm sure 5.6mb is an even smaller investment, right?