Earlier quoted context omitted.
Stolen hard drive is rarely what you defend from, and arguably might completely not matter if say their short lived session is dead but long-lived password manager one is up. Exploits owning software on machine are far more common than machine itself being stolen. I'd also argue that tying re-login to the sensitive actions is far better way to fight it. Basically have long session for nondestructive actions but short…
Stolen hard drive = Stolen laptop/phone/tablet
I’ve seen businesses put used laptops straight up on second hand market, without barely doing basic formatting of the drives, unencrypted. Even less so on private market.
Heard from security friends also that there are examples of attacks that succeeded thanks to drives found in trash outside enterprise.