It took TWO WEEKS before his Windows Server 2003 was attacked? TWO WEEKS? He should be celebrating!!! Most Windows servers get attacked within MINUTES of going online. Now if he's upset that a vulnerability that Microsoft had published a fix for (five days before his attack) and that he didn't implement that fix, then that's another issue. There WAS a fix, and he didn't put it in place, and so he got infected.
The fact is that a lot of stuff people say about how vulnerable Windows is and how INVULNERABLE OS X is is horse hockey. That there are known exploits against Windows is not an issue. But that there are so many more Windows boxes out there, and that it's targeted systematically by a lot of people is the issue. If anywhere near that effort was aimed at OS X, then a LOT of exploits would be discovered. The key here is that OS X is, like mitchell_pgh says, based on a solid, well built foundation. Flaws can't open the core of the OS the way Windows flaws can. That doesn't mean that there aren't flaws in OS X, but rather that they're harder to take advantage of.