Windows 8 security button..
This could be a nice start. However, it would be very nice it they took a page from the mainframe OS's of old. I will not go into the design details of the mainframe OS but suffice to say any "program" could not crash the OS. The program or application had an address space that it had to execute it and if it tried to go outside that space, the OS crashed the program or app preserving the the integrity of the OS.
The OS needs to be distinct and something that controls the applications and one where you cannot overwrite any aspect of the OS; in effect a read only OS something on an ASIC.
Like I said, a very good start in an attempt to preserve the OS>>