MFA, pin code, os or tpm or browser finger printing / cookie signed to your machine, ip address or ip range lock, reauth over a short but not unreasonable time, concurrent session lock out... I would think there are few options besides just throwing your hands up and admitting failure where someone can just pay $10 for a plug and play cookie.
I don't know about a giant company like EA, but you could really screw with my company's plans if you spent any time on our Slack.
So now I need to consider that any malware could (and probably is) looking for slack cookies to exfil. So, no, I don't really believe there is always going to just be a single point of failure and it's an insurmountable problem.