Requiring a pin means no one can use your fingerprint or your face to unlock your device.
An NSA agent recommended restarting your phone every week. This can potentially clear out malware that doesn't have permissions to start after a reboot.
Yeah I learned about it from reading up on the Israeli hacking software called Pegasus. There were several devices that they could hack in AFU state but not in BFU state.