There is a second question as to whether Windows is still inherently more susceptible to these kinds of attacks (I would guess the answer is yes), but that's kind of irrelevant. The threat exists, why wouldn't you just use Macs or Chromebooks or whatever else? Basically _anything_ other than Windows? Even in the case where you have Windows-only business critical software, just run it in a VM on something else.