So, simply from your 2’s input if Microsoft could ensure their own inbuilt update process to maintain 10S, then people would not need to override it to update a new PC setup.
Actually, it's not really the update process that's the issue here Lee, since even if it's not kept fully up to date it's still inherently more secure than its legacy desktop Windows cousin. That's due to the fact that S mode leaves out so many of the ancient components of Windows, that over time have become easily abused by malware, that it's often not truly affected by these specific vulnerabilities.
Since all programs sourced from the Windows Store must be some form of Universal Windows Program (UWP) application, even if they were just modified using a Windows Bridge, they're inherently more secure than their Win32 cousin as well. These Desktop Bridge apps also behave like non-hybrid "native" UWP apps. They do not modify the system registry and are essentially sandboxed from the OS to ensure one-click uninstall with no orphaned DLL files in the Windows System directory.
The positive here is that these UWP apps inherently benefit from the additional security of not having the ability to directly affect the operating system and other apps, which is where many Windows security issues occur. It's this improvement in isolation that makes it much less likely that any malware can gain control of the operating system, even if it does actually have an individual component that might itself be vulnerable to attack.
So as TMiq stated above, if I were still involved in corporate IT support I'd also use S mode whenever possible, since it removes or at least reduces the potential that many attacks might work.
The difference with S mode over most techniques used in the larger corporate or enterprise business communities is that it's just as available to both small business and consumers like yourself. So rather than switching out of S mode and losing the inherent security it provides, you'd be better off trying to find either new apps or hardware that support it.
As I mentioned earlier, it's difficult to get most anyone, let alone consumers, to take the time to understand what S mode truly means to their security. That's because unlike you, most won't even take the time to read a short discussion like this one.
Referring to TMiq's final comment, I think it's clear that Microsoft's intent, as with Windows 10 itself, is to bring more and more app developers to the UWP development community over time. Eventually getting to the point where they can remove the ability for any non-UWP apps or supported hardware to work with Windows period. At that point, S mode can become standard Windows, with no possibility of "upgrading" to a less secure, legacy version.
Rob