Control software, or for that matter, software for a sufficiently narrow domain, tends to come "with bugs" and "for compatibility reasons you need to run this on OS/release version X (which is probably what the vendor ran at the point in time when the software were minted/released).
I've had the displeasure of crossing paths with both the linux and windows variety of this.
In some cases you can ignore the vendors and just upgrade, and jump through some amount of hoops to make it work.
I'm sure in most cases you could engineer around this with isolating it from the world, although it may be non-trivial since it'll probably want to communicate over a network of some sort. Although - exactly what is needed in terms of achieving that may be less than well documented, it costs time and money, and is maybe not really budgeted for, there's aggressive installation timelines, and the security part is probably the first thing to get slashed from when the installation timelines starts slipping.
The vendor just wants to sell you a black box, and preferably not touch it ever again after they've sold it to you. (Actually - some even do sell you a branded, badly engineered, stock PC running some variety of windows or linux or bsd, to control your winch/navigation/foundry/whatnot).
I have witnessed "IT for offshore", in which a vessel is docked for X days, here's a list of things that we need to do, after X days the vessel will depart. You may have a few days on top of X days if you can leave somebody at the vessel, after X+Y days, the vessel needs to be somewhere in an operable state, because we have a commissioned work to perform.
For say running a foundry, I'm sure much of this is similar, except the foundry doesn't have go anywhere - but having your foundry do nothing is exceedingly expensive, and making changes during production comes with a different set of risks.
People have probably complained somewhere along the road, disagreeing with the risks, and somewhere higher up in the chain, the choice were made to take on the risk.
Microsoft Windows has got a major lock on the industrial control systems industry. Almost anything being produced today has a Windows machine in the workflow doing something critically important, from monitoring fluid flows to running microchip programmers and test stations.
"That's the way it's always been" isn't a valid excuse for continuing to make something unsafe.
They did not accept crippling ransomware by using Windows. Nobody does. This attitude is fatalistic and somewhat juvenile.
They may have implicitly accepted crippling ransomware by not having sufficient internal security processes.
https://www.intego.com/mac-security-blog/osxshlayer-new-mac-...
https://www.zdnet.com/article/eset-discovers-21-new-linux-ma...
(I'm going to guess it's a big NO on the first one, because no one uses Macs for critical systems.)