2FA for users. To comply with UK Cyber Essentials certification and ISO27001, it is best if all software used has 2FA enabled. This might be directly on the site, or by proxy via SSO or login with google etc - in the latter, it must be possible to disable login using just email to enforce the security standards.