So I was updating my account info and noticed that there isn't any account security, except for a security question... We're in 2021, and ZoS hasn't even implemented a basic level of account security. We, as a consumer, need to kick up a fuss about this more than anything in the game right now, as this can have some serious consequences.
I know there is an email check when logging in via a new IP... however, that goes to the email account linked to your account. If your email account is compromised, the basic "2FA" has failed (if it can be called 2FA). For 2FA to be secure at the basic level, it needs to not be linked to your account in any shape or form (e.g. Google Authenticator).
There is obviously some basic level of security you can do to try and secure your account as much as possible, such as making sure none of your passwords match or are similar, your email account has 2FA, your security question has a fake answer. But this isn't enough... the first hurdle isn't secured properly, the first hurdle being the ESO account.
tldr: ZoS, we need proper 2FA