You eliminate a ton of "complicated, probably exploitable things" in spaces known to be commonly exploited. Oddball image formats, the Javascript JIT engine, "complex" messaging (Facetime, MeMojis, that... entire ecosystem of weird-not-text-not-image stuff that Apple does), WebGL, WebRTC, link preview processing (I expect a common 0-click exploit chain is through that system), and probably some other stuff.
The phone/tablet is entirely usable without this stuff. Some websites don't render images properly, "that one guy's website" doesn't do the animations, but you can individually bypass Lockdown mode for sites, apps, etc - and you still get the protections for everything else.
And if you're a web developer or app developer, please. Test your website on an iOS device with Lockdown mode enabled. Pick image formats that render properly, it's not hard. And if your app requires something that isn't supported in Lockdown mode, that's fine - but please show some sort of useful error message that indicates that, perhaps, this crash/glitch/whatever is the result of Lockdown mode, and you can disable it by following these steps. Then, also, don't sell to some random purchaser of apps.
But Lockdown mode really, really helps reduce the attack surface. Try it. You'll like it! And it might just help prevent getting you popped by this sort of crap.
... then install QubesOS on your full computers and don't look back. ;)