When off, you're relying on the strength of the FDE passphrase and whatever key strengthening they implemented, and that the OS didn't leave some key fragments somewhere (accidentally on flash, which would be very bad, or remanent in memory if it has only been off for a short period).
Using a long alphanumeric (>12 random, >20 passphrase), not installing random apps, keeping it patched and keeping it powered down is probably the best you can do. I wouldn't use the baseband comms if I could avoid it, just a huge 4G attack surface.
[0] https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app...
This is even good practice if you go to public places where you can get your phone stolen.
Also, which Android versions? Stock Samsung or an alternative rom? (My S6Edge is "stuck" on Android 7 without replacing the OS with a non Samsung alternative. My S4 is running a much newer Lineage Android version...)