There is some truth in what you say about the risks of older machines. Especially when lost of small businesses use Win 95 and Win 98 machines for thier work files and don't need to change. It makes them especially vulnerable.
The alternative isn't very nice either-constantly upgrading in order to maintain functionality.
It is sort of a catch 22. MOst people are somewhere in the middle between these two extremes.
I suppose that for older machines changing the OS to Linux might be the best way to make the machine secure, but people on Win95/98 machines usually aren''t very proficient with Linux.