Earlier quoted context omitted.
Losing passwords is bad because they get reused. 4-digit pin not so much, debit card is basically the only thing that uses it.
You don't have to re-use passwords. In fact, don't re-use passwords. Keeping them in a password manager helps a lot with this. I have over 50 unique passwords which are all long, generated random strings. But there are a few websites, including British Gas, which get shitty weak passwords because they pull dumb crap like this in the name of "security".
If they didn't then password breaches would barely matter.