Passwords should be long and complex.
Passwords should be different at each site to limit your attack surface area.
ANY and ALL financial sites shall have a two-factor authentication turned on
Your phone is far less secure than an actual token based system because criminals can clone your phone by going to Verizon or AT&T with your phone number and requesting a new SIM
Recommend using a different email account attackers do not know about.
Google Voice is better being an attacker cannot run to a local cellphone store to get a new phone, transfer your service, and get your text messages.