I think everyone always gets the direction right the first time. That’s why, when it won’t go in, and you rotate it 180, it still won’t go in and you have to flip it back to the original direction to finally get it in.
My guess is you were burned more than shocked.
The company is cards?
It seems like you are trying to protect against a compromise of the user’s device. But if their device is compromised then their session is compromised after auth anyway and you aren’t solving much with extra auth factors.
It sounds like you are already doing this!
Congrats and good luck!