Earlier quoted context omitted.
If you’re at all serious about security and not user convenience, you deploy BitLocker with a PIN instead of TPM only. And then a whole class of vulnerabilities goes away.
If you are at all serious about security you don't consider Windows. Depending on how serious you are you also don't consider MacOS. And then you kinda have a couple of things to chose from but ultimately you need to build your own security depending on your attack/threat model
But also, threat models and the best way to mitigate them aren't really a linear scale of being to , but a complex consideration of a particular situation.