But are the security experts actually safer online? The study seems to assume that they are. It may be a fair assumption, but it would be interesting to know if it actually is true or not. It would also help validate the security practices. If it turns out that the security experts got infected just as much, or only slightly less than the non-experts, then following their practices might not be worth the effort...
Security experts may use a lot more password managers and want to use unique passwords, but you could say that's just because they have a lot more accounts than normal people. Most people have a couple accounts for social networking, their bank, perhaps a local library... experts usually work in the field, spend their days online in an office, and have lots of accounts for various tasks or activities.
The attack surface is very different: lots of accounts versus just a couple. Lots of time online browsing various sites versus browsing your average social network in spare time. Perhaps I'm overgeneralizing, but it probably matches a good percentage.
And then there is the definition of "safer" or "expert". Are you an expert when you got a degree in the field? When you followed some online courses? When you work in the field? Or when you read a lot about security?