A. Doing security is expensive and viewed as a cost burden at a lot of non-technical focused companies. Lots of businesses hedge their bets hoping that a security incident won't be as expensive or detrimental as having a great security posture. Sadly often times they aren't wrong either.
B. Security compliance standards are dated and opinionated, requiring rigid solutions to complex ever changing security threats.
Both of those can drive the narrative of pushing for tooling that offers the least amount of resistance to implement and be able to claim "secure".
Additionally IT and Operations teams are constantly getting more duties and can be some of the first teams to get rightsized and viewed as "cost centers" in some companies. I've seen teams reduced 50-80% over the years with expectations higher and security compliance becoming the last on the list and then gets the least amount of energy and attention.
All the device drivers you need to talk to 8K displays, boarding pass printers, passport scanners, et cetera are actually there. Not necessarily good, but they're at least, like, available and sort-of tested.
Then, the "centralized IT management" story is actually quite decent for Windows. You have AD (no, sorry, Entra Ultra-Secure, or whatever it will be called next week), group policies, deployment kits, kiosk lock-down modes, controlled updates[1], and what-have you.
All of that is, ehm, sort-of lacking on other platforms. Actually, the worst that can happen to a well-meaning IT person is having to deploy and manage some proprietary "ultra-secure" Android abomination, especially after the single source of that goes inevitably bankrupt...
([1] Except, of course, when the outsourced elite security ninjas feel the need to chase down dangling pointers in kernel mode in realtime. They, of course, get to do whatever they want because, hey, National Security!)
But here's how things work from the perspective of a small-ish airport, healthcare, or finance operator (DMM is a D*mb*ss Middle Manager as employed by a regulator, WIP is the well-meaning IT person on said operator's end):
1. DMM: You're critical infrastructure! It's imperative that the Bad Guys don't take over your PCs!
2. WIP: Well, I'm pretty sure that our locked-down kiosks are pretty secure? We have separate VLANs without Internet access, basic anti-malware and basically only allow our TN3270 and digital signage stuff to run?
3. DMM: Oh, sweet summer child! You will connect to the Internet to share operational details with us and to show all-important public service notices at all times! And, you will employ an elite ninja strikeforce to keep Al Qaida out of all of that!
4. WIP: ehm, yeah, well, I'm pretty sure we can't actually afford any elite ninjas? I mean: we run, like, an entire nation from a run-down office in a low-wage country?
5. DMM: Nevermind, my lad! Here is a list of Approved Vendors that will Keep You Safe (and, most importantly, pay my humble consulting fee on the lowdown)
6: WIP: Err, that just looks like a badly implemented rootkit?
7: DMM: Well, it is what everyone runs to stay secure! And we do want to stay secure right? Let me talk to your CEO -- I see we're set for a round of golf tomorrow...