A couple of days ago, I discussed Nostr with a bitcoin miner, who also teaches people and helps adoption on the ground here. He said the main reason his organization isn't publishing notes is that he doesn't want to hand the org's nsec to his employees. So, it's true, technical people are certainly aware of the risks of using a single private key for identity.
I'm not sure if key rotation is more important than delegation, or sub keys, or than even just a good UI for submitting notes to someone to sign.
