Imo any attacker that has access to the hardware cannot be countered by software. There always is a badusb or sodder this here chip type attack possible against any attempt at locking up your pc.
You can encrypt and backup, but any legends about tpm, bios passwords, weird hardware encryption features and keys are moot once an attacker can read what transits on the pcie or memory bus