At BCM, we offer two types of two-step verification (2-FA), with Google Authenticator being the most secure option.
Here's why: If someone gets access to your email account, that person can change your password by requesting a recovery code. Once they have access to your account, the same email address will receive a verification email. In principle, this person can therefore get full access to your account right away.
However, if you use Google Authenticator, there's an extra layer of security: a code from your phone. Even if someone has access to your email account, they won't be able to get into your BCM account without access to your phone and authenticator code.