P.S. I ran Windows 2000 Pro from 2001 to 2008, with a 56k direct modem connection.
Warez, cracks, P2P, IRCing, you name it. Public IP. Software firewall (Sygate) on the OS. Opera browser.
A regular user would have 0 prudency to use it, they would somehow end up with firewall disabled, IE installed and a ton of shitware on the infected computer in two days. For me it was a daily driving clean computer that carried me through comp. sc. college, early sidegigs and work.
Back then, as well as today, 99% of security is in the usage patterns.
I was using macOS for 12 years (2013-2025), never got problems with any malware on it. I used to have Windows dual booted. I used it like 1% of the time for some gaming. I had 4 computers for macOS (hackintoshes) for that period and Windows was always modern versions of Enterprise LTSC. I never visit anything on the Internet despite youtube, google and famous websites (e.g. reddit, strackoverflow (rip) etc)
All security updates.
And you know what? Somehow I've managed to catch miners two times. I have zero bad patterns of insecure behaviour, scammers tried me to social engineer me like 15 times, never succeeded.
One time miner started working after upgrade of GPU to GTX 1080 Ti.
Second time was last year. It made an exclusion in Windows Defender for it. All I did before that - I've installed AnyDesk from official Website, Parsec from official website and DuckDuckGo from Microsoft Store. Also updated klmcodecs from official website. I know that malware can go even from Microsoft Store.
I never tried sandboxes on Windows. Anyway once you catch malware it's too late for your data and your system is compromised. No "miner_deleter.exe" does not guarantee that your system is yours. And I have few friends who have no viruses for years. I catch them occasionally even if I don't really use Windows 99.9999% of time now.
Anyway from my expertise, there is no really a problem to just use FreeBSD/Linux on some weird laptop with encrypted system drive and encrypted virtual machine inside. If you're a trader, you probably will need 3x3 displays of matrix
I mean people require to work with financial stuff all the time. Just have clean, controllable environment for that. Not necessarily FreeBSD, you can use VirtualBox with Linux and doing zfs snapshots of built-in snapshots in VirtualBox. Encryption.
If you just want to save your bank card to pay for lavender raff online - I can't see why you're so concerned. Any bank should have 2FA per each payment except some trusted platforms.