Yes, IT sec is sort of a rabbit hole. There is always another attack vector right under. If its not software, then its firmware, if its not firmware then its the chip..etc.
Normally, you would consider where the biggest risk is and set up your security accordingly. Unfortunately, with such an intrusive, state-level actor, you have to assume the worst.