I'm lucky for the most part in that my company is very cutting edge and running latest windows and pushing software devs/vendors to stay as up to date as us. But support for "new" tech like Yubikey authentication is very slow to encroach in these industries. Yeah I know Yubikey isn't new in the holistic sense. but its a lot "newer" than a lot of the tech in these industries.
What 2 factor is used isn't important - what's important that you use some sort of 2nd factor (your password - something you know as being the first factor) that's limited to one physical device (something you have) that is not easily moveable. And NO, SMS is NOT 2 factor since you can bump a cell phone number from one phone to another pretty trivially with most cell phone companies (unfortunately). SMS is about on par with emailing you a code for secondary authentication. A barrier for a remote hacker who doesn't have physical access to you or your stuff, but not that high of a barrier.