How should the company be protecting user data, when - like you said -, the average person doesn't take cybersecurity seriously, are not techies, don't use a computer outside the office, and just want to log into their account with a password they remember?
Are you basically just saying the company should've enforced 2FA? Or maybe one of those "confirm you're logging in" emails, every time they want to log in?