When you can remotely prove that the entire boot chain has not been tampered with, it’s much harder to load cheat software in the kernel layer. Of course, still possible, just harder and easier to detect.
Private cheats usually require being vouched in, sometimes with ID scans, sometimes physically shipping you hardware.