Key leakages are a big big big problem. Keyrotation are a priority afaic.
Discussion
Also need a hardware note signing device. The Blockstream Jade open source hardware should be sufficient. It has a screen and camera and enough programmability to support HD keygen.
There are a couple of hardware signers that exist out there already, but nothing is very mainstream yet.