Android phones don’t have a BIOS for the same reason that Macs don’t have a BIOS and Raspberry Pis don’t have a BIOS — they run on the ARM architecture, not the Intel-compatible PC architecture.
As such, the bootloader system is compliant with a totally different reference system; ARM (Acorn Reference Machine) has been around almost as long as the IBM PC compatible architecture.
As for the “why are phones more locked down” bit, it’s because they’re supposed to be appliances, not general computing platforms. You want your phone to always work, so if you receive a phone call, text or email, it’s likely going to work.
Although the real answer is that if you buy a computer, you own the computer and get to decide what goes on it (well, unless it’s locked down to Windows or macOS). Phones contain bits that are owned by your carrier, bits that are owned by the manufacturer, bits that are owned by the software developer. And each of those groups doesn’t want anyone else messing with their private software.
Yeah; seems like a no-brainer for Russia; just look at the cost/benefit; they fielded two jets that did some useful reconnaissance, and in return the US and Canada expended millions in a show of force that accomplished nothing else.