The list makes every item a problem for the employee when in reality it's a problem for the company itself. It's the company that needs to implement and IDP and define SSO/2FA policies. The company is the one that ought to make following the rules the default - create policies to prevent saving passwords to the browser, etc. Employees do play a role but companies need to understand that it's on them to create sane policies by default