There are also 1.5 billion active Apple devices including Macs and tablets, and 2.5 billion active Google Android devices.
Given Linux and other computing devices to add to the above. Microsoft really has an only (at best!) a 25% share of the world of computing devices.
One can split hairs about being the monopoly leader in their niche, but the thing is... PCs and Macs aren’t the main form of computing anymore.
It would be hard to argue that Microsoft should be broken up because Windows is the future of the market and is illegally being exploited to sell more Azure, or Xboxes, or Microsoft Office, etc.
[1] https://www.zdnet.com/article/bigger-than-windows-bigger-tha...
Geer & co wrote their paper right after the first "Summer of Worms", in which the insecurity of Microsoft's software was such a hot topic that there were congressional hearings on it. His analysis presumed that Microsoft wouldn't commit itself, organization-wide, to correcting the problem, because no other large organization had.
But that's exactly what Microsoft did. On an edict from Bill Gates, the whole company pivoted towards security. They hired a huge number of software security people and contracted out essentially the entire software security consulting industry to assess everything from the TCP/IP drivers to Minesweeper (they now host an internal conference, "Blue Hat", to socialize the results of 3rd party audits from blue-badge vendors and internal researchers). They delayed and re-roadmapped whole projects around security, Longhorn being probably the most obvious example. They trained all their software teams on software security, and enacted company-wide controls on "safe" and "unsafe" library functions.
Essentially, Bill Gates did the same thing in reaction to the Blaster worm that Theo de Raadt did with his fork of NetBSD: a site-wide top-to-bottom audit (I was, somewhat peripherally, involved with the OpenBSD audit of the 1990s; I had some findings and wrote the advisories but was very far from the most productive person in the project). But unlike Theo, Gates had a cubic fuckload of money to throw at the project, and it showed.
The results, I think, more or less refute Geer's argument. Microsoft was able to (significantly, albeit incompletely) address its security gap because it had the resources to do so. Moreover, each major component of Microsoft's software security risk was, individually, huge: a desktop operating system, an office suite, a browser, etc. All required vast resources, and many were able to effectively share resources between each other. Diverse, (necessarily) smaller organizations could not have pulled this off, and, had they existed in 2004 when Geer wrote about them, they'd have started with approximately the same tech debt Microsoft had.
And so today, if you're looking at a desktop operating system and choosing between one secured by the former monocultural bohemoth and another run by a dedicated and passionate band of volunteers, you will in fact usually be better off with the former. If instead of desktop operating systems we look at mobile platforms, the difference is even more stark, to the point where if you're not using either Apple, or Google's flagship supported platform, you're almost surely running something with grave vulnerabilities.