We did not provide a definition of what "staying safe online" means. As a result, some participants might have thought more of protecting online accounts, while others focussed on keeping their systems from getting compromised, etc. But coming from a non-technical user the question would be likely to be framed just like that: vague, because users don't know what the biggest threats are and what they should defend from first.
The truth is that we don't know if security experts are actually safer. Maybe the fact that they are experts makes them more confident that they can deal with an incident if such a thing arises. So it might be that they take more risks, but then are simply better at fixing things when they break.
We also don't have a ground truth for what users should do to stay safe online. Do updates work better than a strong password? Measuring the effectiveness of different security actions as scale is so challenging, that we don't now how to do it.