How signing works without exposing the key
The device is not a memory stick holding a file. It is a small computer that performs one operation and refuses to do anything else.
An unsigned transaction is passed to it over USB, Bluetooth or a QR code. The device displays the destination and the amount on its own screen, waits for a physical button press, signs the transaction internally, and returns the signed result. The key never appears on the connected machine at any point in that sequence.
The screen is the part people underrate. Malware on a computer can replace an address in the clipboard, and the only defence against that is reading the destination on a display the malware cannot reach.
Better devices store the key in a secure element, the same class of chip used in payment cards, which resists physical extraction as well as software attacks.
What it protects against
Malware, keyloggers, clipboard hijacking, phishing sites and a fully compromised computer. In every one of those scenarios the attacker can see the screen, read the files and control the network, and still cannot sign a transaction without the device and the button press.
What it does not protect against
Three things, and they cause most real losses.
A leaked recovery phrase
The device is irrelevant if the phrase is in a photo gallery. Whoever has those words has the wallet.
A tampered device
A hardware wallet bought secondhand or from an unofficial reseller may have been initialised by someone who kept the phrase. New, sealed, from the manufacturer or an authorised seller, always.
Confirming the wrong thing
The device shows the destination and waits for approval. Approving without reading defeats the entire mechanism.
What a business needs it for
Reserves, not the operating flow.
Incoming customer payments have to be received automatically, which requires a connected system and a crypto payment gateway behind it. A hardware wallet sits behind that, holding balances the business is not spending this month, with the phrase stored under a written procedure covering who has access and what happens when someone leaves.
A business settling through a gateway that converts and pays out may hold no crypto at all, in which case the question does not arise.