I have run and managed open systems for 24 years and never felt the need to create my own distro. I worked with a chap to help him create a custom build based off gentoo and it was so much work it just wasn’t worth it unless you are in a highly specialized area of compute.
I don’t begrudge anyone taking on the task of learning and working in Linux. I know some people who’ve spent the last 10+ years working solely in Linux. Good on them.
Making a list that touts some level of immunity to bad actors for any operating system is dangerous. I’ve worked in cyber for almost a decade, and the misunderstanding around how easy it is to compromise an organization let alone a home user is frustrating.
I spend half of my week just talking to engineers and executives to enlighten them on the latest scams and dangers in the field. It’s a constantly moving target, and articles like these don’t help matters.