You should turn on device authentication so it's harder to compromise your account.
I've got two-step authentication for my email account and device authentication for steam on. In order to get into my steam account, someone would need to get my steam password, my email password, and steal my phone and guess the password to unlock my phone.