IPv4 with LAN on CGNAT, toss your IoT on its own VLAN separate SSIDs. I don't bother with DPI but I'm playing with the idea. I typically run Mikrotik hardware. Unifi is simple and has improved a lot over the years, just not my preference. Considering Surcata plus a few other tools for hosted services like gVisor, Falco, Socket dev, Cloudflare WARP, and if I'm really paranoid something like 3proxy. For privacy DoH, VPS Proxy with Zerotier or Wireguard.
ZT has been great but I hate the idea of 3rd party reliance and attack vectors, so I've considered self hosted ZT for internal language encryption or WG and throw a TURN VPS or CF Worker out there.
For Enterprise Security you could go crazy with WG, mTLS, Certs per device, Zero Trust, etc etc.
Whatever you do should be standardized, simple, turnkey, multiple architecture friendly.
But 99.9% are covered with a basic FW, 99.999% with a few additional options and layers, maybe an IDS but IDS is usually more false positives than actual positive idents, which means everyone ignores it and a self-learning AI will probably also learn to ignore it after too long.