Matter is just the protocol from my understanding, it can also be used over Thread, which is a seperate radio and made to replace Zigbee/Z-Wave.

Thread is also IP(v6)-based. But in this context, Thread would go a fair ways toward solving stavros's concern, as it means security could be enforced on the Border Router(s), rather than each individual device.

Yes, this is true, but I think over Thread it's also fairly complicated, as a protocol. I'm not very familiar with it, though, admittedly.