This is also largely based on threat model as something is better than nothing. I don't believe the average person is going to, much less successfully, implement full layered security.
If more people could just:
- Use long passphrases
- Never reuse passwords for more than one service
- Use an encrypted password manager
- Enable 2FA (Preferability via app not SMS)
It would solve a large majority of the issues. It's important to note that most stolen logins are actually from data breaches and malware. Before Proton Pass I stored everything in KeePass, we're talking many years. I have yet to ever have unauthorized activity or login on any of my accounts, I've even been lucky not to show up on any data breaches.
Sure, I got a "FIPS 140-2 certified encrypted USB" which really can just be done with VeraCrypt for FREE (Supply Chain Prevention), used for archive backups, but otherwise just not clicking on links in random emails or visiting sketchy websites.