If you have a Managed Switch with VLAN capabilities, then your new proposed idea and layout make sense.
Your current setup kind of looks like it's double NAT. Which is not great. You want the Protectli router to be the first device after the Arris Surfboard modem. Have the modem be in only modem/bridge mode. We do not want to use the Arris as a router.
No, you want Ethernet not fiber.
Your downstairs router, computers, and your new upstairs switch / Wi-Fi access point are all guaranteed going to be RJ45 Ethernet.
The only part that is fiber is the part running to the outside.
You can put both a fiber and CAT5E/6 Ethernet in, but just a fiber connection will not accomplish what you want. You need the Ethernet connection in order for each floor to have its own wired connection and/or wifi access. That’s what the consumer equipment will use. Otherwise, you will need more enterprise-level equipment and that will add unnecessary complication.