Sigismund
I try to keep my threat model as broad as possible. To protect myself from anything from a hacker to state actors as much as I can, to an extent.
I think I understand what those features do. Having more secure boot process protects me mainly from physical cyber attacks but can also help if I get malware. Now, sure, if I get a malware, then I'm screwed, and I want to protect against it mostly with the use of KVM and sandboxing.
I don't install random crap on my pc, but I do have some games which are proprietary, and they will at least be sandboxed (with flatpak's bubblewrap and wine itself).
I get that security is not simple nor binary. But with the broad threat model, I try to cover everything.