This is missing an extremely important upfront concept: you need to know what you're protecting and how valuable it is. It does no good whatsoever to require every user of a grocery-list app to have a Yubikey to verify their identity. It might not even make sense to have users login at all. The balance between usability and security must be consonant with the costs of implementation.
I believe that was covered, but it was under the context of security policy vs a more direct description. The key point I'd pull out is: "The goal isn't to eliminate risk entirely, but bring it down to an acceptable level." There could be (and probably are) entire books written about how to define what "an acceptable level" means... but that is the same point you are getting at - security is not a guaranteed lockdown…
Build yourself a threat model. It's only you that can decide this.