Physical access has been "game over" security-wise since before there were computers. If someone has physical access to a computer, or a filing cabinet, there is usually a way to get the data out.
If it's encrypted, they might only get the encrypted data, but they can take it home and work on it at leisure.
Physical security has to come first -- without that, nothing else matters very much.
Exactly. Physical access and enough time and you can get into any stored data.