Zephyr includes tools to help with checking the hardening configuration of apps. Principally:-
https://docs.zephyrproject.org/latest/security/hardening-tool.html
Run these before release for all end-user intended apps.
Also ensure our secure updates and OTA are working as per secure design principles:-
https://docs.zephyrproject.org/latest/security/security-overview.html#system-level-security-ecosystem
Also document the threat model for each final app, as well as each Herald module (E.g. Core, Mesh, Modem etc.).