Your account password works anywhere. If it is captured, whoever has it can sign in to your account from any machine on earth, and you would not know. A Windows Hello PIN is tied to the one physical device you set it up on. It is stored locally, protected by the security hardware in that machine, and it is worthless to anyone who does not also have the computer in their hands. Wrong guesses lock the device rather than opening it up to unlimited attempts.
Fingerprint and face sign-in work the same way underneath. The biometric data stays on the device, and what the reader really does is unlock the credential already held there. That is why Windows asks you to set a PIN before it lets you set up a fingerprint. The PIN is the foundation, and the fingerprint is a convenient way to satisfy it.
The habit that matters most is locking the screen when you walk away, which is the Windows key and L. Sign-in options make that painless, because unlocking costs you a second rather than a typed password. If you are setting up several machines for a small team, this is one of the things we configure as standard during new computer setup, alongside the rest of the security baseline.
Always keep a second way in
Fingerprint readers fail, cameras stop being recognized after a driver update, and gloves exist. Set up a PIN as well as any biometric method so a hardware hiccup is an annoyance rather than a lockout.