Also one thing that was missed regarding multifactor, try to avoid SMS-based 2factor at all costs. These messages can easily be intercepted by attackers (there have been multiple talks about this over the past few years). Ideally you will want to use a U2F token like a yubikey or solokey but another good option is using an authenticator app like Google Authenticator. Check out this site to see what types of 2fa are supported by the services you use: https://2fa.directory/int/
Happy to answer any other questions - I hack for a living and also teach hacking at university I also take payment for any consulting in CCs (lol)
https://solokeys.com/
https://www.yubico.com/products/yubikey-5-overview/