CISA Releases Guidance on Protecting Organization-Run Social Media Accounts
cisa.gov
cisa.gov
Disclosure: My company is offering a web-based 2FA authenticator (https://www.daito.io/) that explicitly is for sharing 2FA tokens, but not usernames+passwords, thus eliminating a single point of failure. I regularly have discussions about why and sadly why not people are using 2FA. There are tons of small business & mom+pop shops out there who are at risk.
I hope the guidance gets upgraded to a mandatory requirement (as some platforms do) sometime soon.