With a closed ISA, the only manufacturers are closed-source and I can't verify the chip is secure under any circumstances.
With an open ISA, I may not be able to verify all designs are secure, but, I can verify that some are secure and choose one of those.
You are conflating the ISA with its hardware designs. I'm not an expert, but imagine an ISA being like a C library API, in that case the hardware would be the APIs implementation.
With a closed ISA, the only manufacturers are closed-source and I can't verify the chip is secure under any circumstances.
With an open ISA, I may not be able to verify all designs are secure, but, I can verify that some are secure and choose one of those.