if they don't have the password they're not gonna get anything more or
less than if they know the password to Filevault.
That's not really true: you can remove the disk from the notebook and
mount it from another computer, regardless of the password protection on
the notebook (eg, OF/EFI password, user accounts). On a MacBook the disk
is even end-user removable.