Email is not secure, no matter what service you use. It is transferred in plain text between providers.
1. Encryption in transit - Yes, indeed unencrypted SMTP is common. SMIME and GPG are not as common as they should be
2. Encryption at rest, server side - 99% of providers don't do this
3. Account security - supporting MFA, u2F etc
4. Application security - If there is an official application, does it store saved mail property (ie, not in a big dumb PST file)
So yes, somebody could sniff some plaintext SMTP email regardless of your provider, but the other features are very valid and important.
A backup of emails in gmail can be downloaded over IMAP and saved offline. Offline searches in Thunderbird are many times quicker than within gmail.
The best time to do this was yesterday, but the second best is right now!
It's not gonna get better otherwise.