The PIN on a Windows machine is a secondary credential to unlock the primary local credential, with the primary being your actual password.
Also, as mentioned in the sibling comment, PINs are just device-local credentials. They don't necessarily have to be numeric-only and can also be very long.
You can have your computer re-challenge you for a full password on some interval. So have it force you to use your password on your first login of the day, then you can use your PIN to hop back in during the day and then have the PIN option time out after so many hours. Same with any of the Hello credential options.
After too many failures with a PIN, it will disallow the PIN authentication entirely. So, its length isn't really a problem, it'll start to disallow PIN attempts after only a few wrong guesses. Once again, also configurable. Meanwhile, it'll always still allow a password although it'll start trying to slow you down on password attempts.
PINs are supposed to be stored on the TPM or similar secure platform module, they're not stored on the local computer storage. So, there's not some easily accessible file to do brute-forcing outside of the computer.
While consumer Windows isn't really Windows Hello for Business, the same basic ideas of PIN security are the same. Here's the FAQs on that which also go into some depth of why PINs over passwords:
https://learn.microsoft.com/en-us/windows/security/identity-...