Best practise. If you are looking for vectors to get the keys you have to look out for:
- Is the baseband processor secure
- Can the key be read out "in flight" (RAM, EEPROM, CPU...evavesdropping on a bus...whatever)
RE: Physical security of a device.
Maybe you can get it like the KRBTGT key on Windows servers by creating a dump. You're set then

OTAR is a must.
Are those devices implementing AES256 under review by independent cryptopgraphers? Is there a security chip like a TPM in those devices? An enclave?
My idea would be implementing my own CA with certificates for those devices joined to my network. Strong authentication which enables reliable encryption.
Then again...if you want to commit serious
crimes business you better buy a politican than monitor police radio.
Monitoring police radio is for freaks, "serious business" people have things like the WEF.
Maybe that's why we as people have to carry covid certificates and the government has become a certification authority (CA).
Oops!