Re: The problem is ...
"To turn them is going to take something pretty cosmic, something so bad that it would threaten the companies very existence. And I am not talking about the malware groups - this would be something that Microsoft did to them."
Don't discount the malware groups and don't also discount that their effects, on further analysis, can be partly seen as something Microsoft did do to the victims.
There was a story on the Beeb site the other week about a reasonable-sized UK haulage firm - one whose name I recognised from seeing their fleet on the road - that was taken out of existence by malware and we have seen several large UK businesses severely hit this year.
It's not inconceivable that a few board members of some of these companies take a bit of time to reflect over Christmas and come back in the new year asking "How did this happen to us?" and really start digging. They then discover that being anything through and through is a bad idea. They discover that "Enterprise versions and all the active directory, policy settings etc controls that come with it" didn't prevent what happened. At that point some of their senior IT professionals are going to get asked some questions as to what they're going to do about it and if they don't come up with convincing answers (more of the same won't be convincing) the questions will get put to other IT professionals who can answer them.
How many high profile migrations by high profile victims does it take before a few other boards decide the time to go is before they get hit?