ok, I haven't done one of these in a while, but here's a #SecurityHygiene / #CoSoSec post.
A reminder: turn on 2 Factor Authentication (2FA) this makes sure that if an attacker has your password, they still can't get in without a token that you should physically possess.
If given a choice, do not use email or SMS as this 2nd factor. They are easily intercepted.
Use TOTP (app based 2FA list here: https://www.protectimus.com/blog/10-most-popular-2fa-apps-on-google-play/)
Or if you feel like dropping $50 for real security, get a FIDO2 key.