Even less flippantly though, we inherently know this. How many things do we do every day that could be "more secure", but "more secure" gets in the way? Do you use memorize 256 character unique passwords for every site and system and refuse to record them even in a password manager? Do you use GPG encrypted emails and only E2E encrypted messaging services? Are all your home network devices independently fire walled, with strict in AND outbound rules ensuring they can only talk to the specific devices they should be able to talk to and only on specific well defined ports? Have you hardened your home network against data exfiltration via DNS queries? Is all network traffic fully encrypted with mutual client and server cert validations? If you've answered no to any of these questions, you have chosen to prioritize something else over better cyber security defense. And it's probably a good bet that at least some of that is because doing these things would actively get in the way of doing what you actually want to do with your electronic devices. You've knowingly chosen a weaker defensive stance to do something else instead.
Attackers on the other hand have no need to choose weaker attacks on your defenses in order to do something else instead. The attack is the point of their usage of their devices (and yours).
You might argue that the attacker might choose a lesser profile in order to remain hidden and beneath detection, but I would argue this still isn't the same choice. Given the option, no company would spend any time or money on resources for cyber defense. They would rather spend all that time and money on their actual business. But Attackers would spend time and money and resources on their attacks because those attacks directly serve their goals.