>why do many companies use SMS as secondary auth (for the "2" in 2-factor)?
Because they don't know about TOTP or HOTP, and they instead decided to use a terribly insecure protocol as the basis for user authentication? The onus is on you to prove SMS is better than a shared secret + a nonce.