The consensus for a secure wallet is an open source cold wallet like the hardware wallet you mentioned or a software wallet on an airgapped device. There are different types of open source hardware wallets and you can choose any from the list
here. For hot wallets been used on airgapped device I will go for
electrum wallet, Although other open source wallets can still serve same purpose.
You need to understand that the safety of your wallet also depends on how you safeguard your wallet seed phrase. There for a proper offline backup is advised
Your last paragraph is completely right, and I was going to mention this in my comment, so, seeing that you've already said same thing, I thought I should quote, thereby acknowledging that you've mentioned same as well.
Overall, it is very important that we as users understand that we are our own security, a person can use either a hot wallet or cold/hardware wallet for several years and never get hacked or lose his or her funds, but another may do same and get hacked the very next day.
So, in the nutshell, our funds is just as secure as we ourselves chose to tighten our wallet security, ive personally been using myceluim wallet on mobile for a several years now, since 2017 actually, and never have I been hacked or had lost funds in any malicious form, I own a hardware wallet I bought of recent, but haven't started using it yet.
So, in the end, ones we chose the right type of wallet, like open source non-custodial wallet, could be a cold or hot wallet (both makes sense actually), the security of our funds at this point is completely in our hands.