I've been offered a shot of a mates lte router and sim card so I shouldnt need to do much more than just plug it in
Yes, my solution for this eventuality is an industrial LTE modem with an Ethernet port, which Just Works in much the same way as a DSL/cable modem or fibre ONT without any fucking about with WiFi. Plugs into pfSense as a second WAN. (Dual-WAN configuration left as an exercise for the reader, I've never come up with a satisfactory automated solution, but that's mostly because of trying to make use of AAISP's backup L2TP service, which unhelpfully breaks the primary connection's routing when brought up.)
My IoS devices operate in an isolated VLAN with no internet access as a matter of course, which rules out about 95% of commercial products, but means they don't care if the internet connection goes down. (The MQTT server and firewall are still single points of failure, unfortunately.)