Thomas, I would love to get some insight on OS choice from someone so well respected in the security community, and maybe a short mention of why OpenBSD's security laurels may not be well deserved.
OpenBSD's incredible code quality quite obviously doesn't apply to the ports tree (and that's not their fault) but we quite often ran into less popular products and third party libraries where the ports were updated in the order of weeks later than things like RedHat RPM for the latest vulnerability.
At point I backported a hotfix myself, the requirement of which was not conducive to security.
Disclaimer: This was years ago, things may have changed.