People who deploy professionally / on scale / create customs images for other things are tech savvy enough and know how to disable SSH - no need to have it disabled by default.
I think you’ve solved your own problem. The people that are savvy enough to do it know how to enable it and it’s not a real impact to them. But by disabling it, the people that don’t are protected. Which is why this is a standard practice across Linux distros.
Bet. Give me puppies as a service.