Thanks for the great post!
I’d add some caretaking for the default disk encryption. I wrote about it in this thread.