I think there is a lot of posturing and conjecture in this thread.
It is true that apple's platform security architecture is robust. It is also a fact that this is no guarantee of safety. No one will disagree that hackers and nation states are actively finding, exploiting, and remaining private about system, browser, and cryptographic technology vulnerabilities.
May I encourage some levity?
Threat protection software is often marketed as malware/anti-virus software because "endpoint security" does not make sense to the average consumer. Whether or not malware and viruses are prevalent on MacOs, what the original poster and most people who have this concern are asking for is software that puts up additional guardrails around their computer usage, either because they know their behavior could invite exploitation, or because they know they have no idea.
Apple recognizes that different individuals and organizations may have different standards or needs for throttling behavior. To that end, Apple has included an API in Catalina and later for independent software vendors to do exactly that (literally called "Endpoint Security"). Additional mechanisms can be utilized that have not traditionally been native to most of Apple's core operating system offerings (e.g. more informative inbound/outbound connection monitoring, ad/popup suppression, javascript execution monitoring, and content signature scanning).
Software that leverages these APIs or takes extra measures to alert and protect customers is not useless.