Security
Requiring a second proof of identity beyond the password — and the factors differ enough in strength that “we have 2FA” says almost nothing on its own.
Also called 2FA · MFA · Двухфакторная аутентификация
In ascending order of resistance: SMS codes, which are defeated by SIM swap and by phishing pages that relay the code in real time; app-generated codes, which survive SIM swap but are still relayed by a convincing phishing page; push approvals, which add fatigue attacks where a user eventually taps yes to stop the prompts; and hardware keys or passkeys, which are bound to the site's origin and therefore cannot be handed to a fake one.
For the accounts a business is actually attacked through — the mail account, the ad account, the social profiles, the domain registrar — the only category that stops a competent phishing attempt is the last one. Everything above it is a speed bump.
Protecting the business accounts strongly while the mail account behind them keeps SMS recovery is a lock on a door with the window open. Attackers do not attack the ad account; they take the mailbox and ask it politely for everything else.
The definitions are the easy part. Whether the figure on your dashboard was computed this way is a different question, and usually the more expensive one.