I use the Trezor Safe 3. It's cheap, has a hardware security chip, XMR support, Open Source Firmware (BTC only if wished for reduced attack surface) and a good long security track record. Nice bonus is the web app which can be used on GrapheneOS in Vanadium, so no dedicated app or Play Services necessary. I don't think it gets any more secure than this...
I'm not a fan of Trezor, just of really good products. There's also the BitBox2 in case that's a better fit for your needs. But yes go for a Hardware Wallet, and don't go for Ledger. You'll be fine this way. :)