Just boot your os from a disk when ever you use your trezor
Encrypted disks (LUKS, Truecrypt...) are also good, but you're still vulnerable to hardware key-loggers.
I think the best is not to let the device accessible as Mike suggests. Either carry it always with you or lock it somewhere.