Everything here is my opinion. I do not speak for your employer.
Friday philosophizing: If your threat model includes untrusted devices plugged into your wire, you might as well be wireless. Because wireless interfaces already worry about that.
My latest project is Tailscale: the easiest way to use WireGuard and 2FA.