The difference is that nobody has to actually accept updates that the core team make - and this has happened a few times, resulting in forks, although those cases were for things the core team refused to do - how can you “fork” a security? What is the common enterprise when forking a PoW chain?
Exactly the same way you fork a non-security. Security is a legal designation, not a description of how a particular asset is implemented (in a forkable structure like a blockchain).
> What is the common enterprise when forking a PoW chain?
The developers/promoters of the fork, potentially.