My question is for NXT experts.
I find the login Passphrase on brain wallet to be a single point of failure/weakness for using NXT and NXT related tools! Why? Because most people cant memorize the long pass phrase and they have to write it down somewhere...
What additional measures can one take to secure NXT wallet given how critical a platform it will be in the near future with MGW and SuperNet?
Yes, it's a point of controversy

Some NXT wallets do use a wallet.dat. I think the MOFO wallet does (I didn't name it...)
You can also use secureae.com, which is a web wallet that includes the Asset Exchange, though I think it will still require a long password of some sort - not sure.
People use stuff like Keepass and other apps like it.