Just use a package disabler, a ADB edit or if your rooted you have even more apps to block OTA updates.
Security in real life isn't an issue with Android 9 or higher unless you do something stupid. This stock N10+ has been running on Android 9 for over 2 years with no updates.
The current OS load is over 1.5 yo, still fast, stable with minimum maintenance. I take a few precautions especially with app installations and downloads. Android 9 and higher are reasonably secure even if Google claims otherwise.
So enjoy your current platform for as long as you want. Don't let updates break your phone... they sure as hell can and do.
Redundantly backup all critical data to at least 2 hdds that are physically and electronically isolated from each other and the PC. Time stagger backups to them incrementally as an added precaution. Have a plan in place for password resets and bank accounts (which are insured from fraud anyway).
In the case of malware if you can't completely isolate and delete it within an hour or two, go full nuke and reload. It takes far less time to reload then it does to attempt to optimize and adapt to a new OS version.
Fools leave in fear, pragmatists live within reality.