Windows isn’t Crowdstrike.
And, quite frankly, a well configured and properly locked down Windows would be as secure as a locked down Linux install. It’d also be a pain to use, but that’s a different question.
Critical systems should run a limited set of applications precisely to reduce attack surface.
In fact, there's a couple billion Linux devices running around locked down hard enough that the most clueless users you can imagine don't get their bank details stolen.