I think you're bang-on with "investment in a promising line of business"
> First, organizations continue to depend on vulnerable legacy infrastructure and software, rather than adopting modern IT and security practices. Too many governments still rely on legacy vendor contracts that limit competition and choice, inflate costs, and create privacy and security risks.
> Second, nation-state actors, cybercriminals and other malicious actors continue to target weaknesses in software supply chains and many vendors don’t have the tools or expertise to stop them.
Pretty much it's "we're better at security than most other vendors, and we want to get in on those sweet government and corporate contracts".
They're probably not wrong, I would bet Google is better at security than most companies are. One way of reading "legacy vendor contracts" is "legacy-vendor contracts" :)
> We are also pledging, through the Google Career Certificate program, to train 100,000 Americans in fields like IT Support and Data Analytics, learning in-demand skills including data privacy and security.
Let's take a guess at whose systems they'll be getting trained on :)