Genuinely interested, why would Win7 be worse than Win10 if you had the same network setup, same browser (same extensions) and behaved the same as you do with Win10?
I ask as even at home, my different devices all use the same browser/extensions, VPN and browsing habits. I use established FOSS where possible and the only problems I have had since Windows 98 are from data breaches (nothing I could have prevented with different OS/software).
There is no difference between security and privacy. If you have no privacy, compromising your security is easy. If you have no security, compromising your privacy is easy.
I would not have thought the improvements would have been that significant (I'm old and ignorant).
HeSP is dependent on the cpu? (article noting intel gen 11 and amd ryzen 3 are needed) and ASLR still being implemented on Win7 with http://support.microsoft.com/kb/2639308
We still have to keep a couple winxp and nt boxes alive at work for diagnostic gear (none are online). Thankfully not my job as I am obviously a risk :)
Forced ASLR isn't the important feature (the browsers already opted themselves in). The increased entropy, which doesn't exist on Win7, is important however.
Windows 10 was technically vulnerable, but since Windows 10 has drastically better security features, from a defense-in-depth standpoint, having Windows 10 more or less rendered most computers immune in practice. (Likely, the few 10 machines infected were intentionally crippled by their admins.)
Bear in mind, Windows 7 is an OS from 2009, 12 years ago. It's ancient from a computer security standpoint.
Whether you are personal or corporate, you probably should be running either Windows 10, or choose an alternate operating system entirely like OS X or Linux.
I ask as even at home, my different devices all use the same browser/extensions, VPN and browsing habits. I use established FOSS where possible and the only problems I have had since Windows 98 are from data breaches (nothing I could have prevented with different OS/software).
Or are we talking about business/corp usage?