If they have physical access, it's over regardless of what authentication mechanisms are employed.

I'd argue that not being able to modify software subjects you to a higher risk because you wont be able to fix security vulnerabilities yourself.

Software and hardware outlive the companies that produce them.

