I used to think that way ... until I did get hit by a ransomware. I figured they got in via a vulnerability in Windows 7, since only my Windows 7 machines got hit. My Windows 10 and Server 2012R2 machines were not breached. I was lucky, I had backups and managed to recover without loosing anything significant, but still it took weeks to scramble and rebuild machines from images, some dated a while back, reapplying updates, etc...
It was a huge wake up call, and I have since begun to harden security even more. But still, I feel at some point law enforcement, government and regulations will have to step in, because this is causing serious harm to citizens and businesses. We do not tolerate such things happening in the physical world (theft, burglary, etc). So why should we feel it's business as usual in the virtual world ?