"Site hacking must be at an all-time high. When IIS was just a teency little minnow with no defenses to speak of it was vastly more commonly hacked then Apache"

IIS has always had a far better security record than LAMP stacks, and historically was about 4 time LESS likely to be hacked (allowing for market share at the time). See for instance

