Even with multisig, each individual key holder has to manage their device, and the steel backup for that device. And there exists possibility of collusion between n of m of the multi sig holders against the other holders. Seems like it would still keep me up at night (though with SVB, standard bank accounts are starting to look shaky too).
Having not worked for a crypto company, curious what the standard best practices are for securing the "keys to the kingdom" (literally).