That said, I don't really consider Windows "secure", when it's still filled with legacy cruft that was written before Microsoft's focus on secure coding. We are still seeing font exploits in 2022, FFS.
The track Windows 11 is headed seems like a decent approach given realities. For whatever reasons, Microsoft's efforts to eliminate legacy cruft has proved unsuccessful/untenable, so the next best compromise is to harden the OS against itself and everything else.
For something more foolproof and secure, consider iPadOS or a Chromebook.
Here’s a useful resource: https://techsolidarity.org/resources/basic_security.htm
It can even change system settings without you noticing
You should feel naked when you manipulate sensitive data with Windows, because you are indeed naked
Hence why most companies forbid their employees to use windows with public internet access for work