home router makers use boards from companies like QC, Broadcom, mediatek etc that provide a base configuration of a board and something like openwrt along with their updated drivers and a patched kernel to go with it. Generally these things run something as old as openwrt 15.05 when it comes to something like even wifi 6. It fits their purpose and time to market is small with a proven track record of stability. manufacturers put their modifications for their product lineup and sell it until they can make money. firmwares generally receive patches through their original SDKs and depending on severity the manufactures will send out updates which can take months since the vulnerability was reported or even patched in the SDK.
If you are absolutely worried about security you can see why the above model is weak to begin with. While you can do all these things in the list, it's not going to protect you from actual firmware vulnerabilities. Cheap routers never receive firmwares beyond like a few months or a year of launch. higher end ones are more frequent but they arent cheap and you can do much better at those prices.
depending on how serious you are about your network, a SOHO will likely opt for something like a router with opnsense or an OS that gets regular patches and then put an access point on top it. This is also tricky as the above issue is still true for AP makers these days as many of them use openwrt as well for their APs since the chips tend to be similar and as a result suffer from same issues depending on the maker and model.
If you look at Cisco lower end hardware like CBW150AX you may find updates (this one was the cheapest Cisco wifi 6 AP I could find) but you may not get the best performance or features which are available in the higher end ones or from other makers in the similar range. So you may consider paying for higher end APs and then you run into licensing etc. An alternative is generally finding routers with openwrt support and putting them in front your router in AP mode but the stability for an office environment is questionable. I have had weird issues with bands locking up and such APs straight up rebooting randomly in the middle of something.
There is really no one size fits all problem here if you are interested in security. You have to start from the OS and hardware first then move to the top of rules and lists and wireguard and keys and policies and separated LANs etc. What is listed above might take your home network from 10% secure to maybe 50% secure (just making a point). Some things will be better but may not necessarily do that much in the grand scheme of things especially if you run a small business.