

Linux does this better by defaulting to files not being executable, versus Windows needing the downloading software to apply a specific “downloaded file” flag to trigger a notice about potentially unsafe files.
You could make a lot of the commands available by default much less dangerous. Stuff like requiring using protected screens more (like UAC and ctrl+alt+del) for enabling the risky stuff.
Also, sandboxing by default would do even more to prevent the worst dangers.
A split would create North Korea 2.0