Great recommendations and they definitely should be followed. The one remaining challenge we have though, is that with very enriched data sets being available to hackers, they don't need your passwords anymore. They simply use their social engineering techniques to bypass this vector. eg.
Hi, my name is ABC, my FF is, I have forgotten lost phone which has all my passwords encrypted on it...... my DOB is, my address is, my email is, my phone is, my medicare number is, my drivers licence is, my passport number is, my street address is....... can you reset my password.....
While many staff will be will trained to stop this attack vector, since we are talking about millions of customers data and 100's of thousands call center staff, some will get through...... they just did get through this vector, with the Qantas centre in Manila!!! This is the new frontier.