SMS is not perfect for security. But SMS is better security than no 2FA at all, and for many (most?) situations, more-secure alternatives aren't viable. The deprecation of Authy or loss of keys has left me permanently locked out of a few accounts. YubiKey and similar aren't ubiquitous enough or usable enough for many users. I've experienced these problems personally and I'm likely in the most technical 1% of users you're likely to encounter. SMS is ubiquitous and users understand it, and is secure enough for many situations.
If you're running a service that requires a high level of security, fine, force users to use TOTP/HOTP or something, but be aware you're going to be excluding some users and adding to your support costs by doing that.