Start by analyzing whichever email service you use.
Add additional checkboxes:
- [y/n] Is SMS the only 2FA method available?
- [y/n] Is there no 2FA at all?
- [y/n] Do they have a history of unpatched zero-days?
- [y/n] Is it possible that if there is a security breach, you won't hear about it because no tech journalist pays attention to this service?
- [y/n] Can someone socially engineer the support team to get access to your account?
- [y/n] If a hacker gets access to your account, can your bank accounts be drained?