Two-factor authentication is the layer between a stolen password and a drained account. It is the cheapest protection on the list, and it is the one that is skipped most, usually for the reason that it is one more thing to manage. This is what it does, how to set it up, and the plan for when the factor is lost.
What it protects
A password is something you know, and it can be taken. A keylogger, a breach, a reused password, a guess. Any of them gets the password. 2FA adds something you have, a code from an app or a device, and the attacker needs both to get in. The account is protected as long as the second factor is not in the same place as the first, which is the condition that fails when people store the recovery codes in the same password manager as the password.
The methods
The market supports the standard options. An authenticator app is the baseline, and it is the one to use. It generates a code every 30 seconds, it works offline, and it does not depend on a network delivering a message. A hardware key is stronger, because the factor is a physical object that has to be present, and it is the one to add if you trade serious amounts. SMS is the weakest, because the factor travels over a network that can be intercepted, and it is the one to avoid if the others are available.
The recovery plan
The setup screen gives you recovery codes, a set of one-time codes that restore access to the account when the primary factor is lost. Write them down, on paper, in a place that is not the same place as the phone that holds the authenticator app. The phone that holds the app and the paper that holds the codes should survive separately, because the failure mode they are protecting against is the loss of both at once, a lost phone, a dead phone, a phone that was in the same bag as the notebook.
Test the recovery once, deliberately, in a moment when you are not in the middle of an order. Log out, log back in with a recovery code, and confirm the path works. The recovery that has never been tested is a hope, not a plan.
Where 2FA is not enough
2FA protects the login. It does not protect the session that is already open, and it does not protect the PGP key, which is a separate factor with its own backup. An attacker with your password and your 2FA code still needs the PGP private key to read the encrypted messages, and the session token to act in a live session. The layers are separate, and the backup for each is separate, and the plan that treats them as one is the plan that fails.
The PGP guide covers the message layer, and the security basics covers the whole stack.