Nowadays, things are really different. Red Hat is large and has a solid track record. IBM has shown its support for Linux over an extensive period. SUSE is now in the hands of a huge IT company.
Consequently, I don't think there is a good excuse in 2014 not to seriously evaluate Linux. In fact, it should be (and often is) the standard option for embedded devices.
Which one are you referring to?
The 'bad' thing now about Windows (and iOS, OS X) I can think of technically at this moment is that it is closed. I would not like to run my company on something closed, especially if there are nuclear reactors, missiles, airports, airplanes, medical crap involved. I want to be able to dive down to the line of code instead of having to ask a vendor why it does what it does. So again, from a tech point of view, I do not understand why any CTO would pick a closed solution over an open, especially when lives are at stake besides him/her covering his/her ass. And that's probably what it usually is; no balls to pick the best thing for humanity (...) even if it's an uphill battle.
Most non-startup companies have a huge tech stack in place. That stack depends in many ways on the OS. If today you win/make a bid for a display in an airport, the first thing you should be asking is "how do I leverage my existing code base". The answer is almost never "by completely switching my OS". Especially in the scenerios being discussed in this sub-thread - lives at stake. I'm going to throw away my multidecade tested code for new code, and call that safer? No, never.
Much (not all) of the code at the company I work at now is Windows based. I'd like to switch away, sort of, but for what? A nebulous "it's open" argument, vs converting man-centuries of work? It makes no sense.
It has nothing to do with "balls", but a cost benefit equation, and a recognition that a 5-10 year old, battle tested OS is pretty darn safe compared to some kernel released in the last 3 months.
Also; when you write software, now or in the 80s, late 70s (before that it was a bit harder unless it was Cobol/Fortran or something), you separate the frontend from the backend. I wrote a ton of 'Windows only' (meaning it had to only run on Windows) software for companies in the 90s and 90+% of that C++ or Delphi code compiles fine on Win + Mac + Linux. I will still say it's about balls in choosing your tech if it's not mainstream aka simply blabbering out: Oracle + MS, but more so now; now there isn't much excuse for picking lock-in tech for the most part.
Not sure what the 3-month old kernel is about; those exist in MS/Apple/... as well; who runs prod on that? So what does that even mean?
It isn't. You have to find completely different loopholes in each implementation of networking stacks to exploit them. Anyone running outdated software is always vulnerable to newer exploits, but the thing with Linux is that is audited by thousands of businesses around the globe, whereas Windows probably has back doors for the NSA through some backdoor dealing with the US gov't and nobody can audit that.
Whereas if I go to the Microsoft site, I can trivially find support lifecycles, details of what is supported, all of my tools pretty much interoperate (no breaking changes), it is easy to download from MSDN whatever set of technologies I need for any version of software, and so on.
I realize I am being unfair - I am familiar with MS support, and not with Red Hat support, so obviously it will be easier for me to find this stuff. But, consider me your average CTO. I don't think the case has been made for long term support of OS as host for my applications (we are, after all, talking about buying an OS to host my applications, not support for servers, which RH is very good at, of course). Hard questions that a CTO should be asking, and I suspect the answers are not going to be good.
[1]: http://www.zdnet.com/microsofts-16-billion-dollar-businesses...