Firstly, they are talking about using microservices which would be ok (I've used a few microservices for specific applications that actualy make sense to service-ify) but I would by no means consider this a safer way of doing things. When you're talking about services run by our government, who isn't notorious for having their network-security done right, I'm very weary of them moving to a microservice architecture.
MTD is another thing that sounds concerning. This seems like the bottom of the barrel of security ideas and looks like it would be far more complicated then the other methods mentioned. If used this along would probably introduce more bugs.
"Education and Training" can basically be summed up as universities being stuck in the 70s and not teaching CS but teaching the Math that CS needs.
The "Liability" section is keeping me torn.
(i) address space layout randomization: this is by no means impervious but it is worth doing (ii) there being several "official" Etherium clients such that if somebody hacked just one client they could not take over the whole network.
I'd liken it to OOP encapsulation or the idea behind linux executables.