I see a lot less security issues now with O365 hosting email than when clients had their own email servers. We strongly encourage all clients to use MFA for everything and the vast majority do.
My problem isn't that it is on the cloud, it's that it is subscription.
The cloud can be scary for the Boomers. I get it. I had long arguments with my former boss.
Think of it like WWII merchant convoys.
A bunch of lone cargo ships can scatter to the winds on their own and hope they can make it across individually. Some might get lucky, but they are all vulnerable if caught alone.
Or group them up in a convoy where you can surround them with a crack team of expert defenders. Sure it is a big juicy target, but can be heavily defended by people who actually specialize in that job and have the resources and tech to do it right.
As opposed to a lot of individual servers where people don't get around to putting on the latest security patch right away.