@emilygorcenski
Risks are never mitigated. They are managed.
You manage risk based on a risk profile. That risk profile gives you an idea of reasonable precautions. E.g. it is reasonable for someone who has infrequent contact with adversarial actors to keep in mind their quality of life features such as biometric login can be over-ridden by rebooting their phone when they may have need to temporarily increase their security.
(Cont.)