One basic thing is to get them to write down unique passwords and keep them in a safe place. Even if they're not using 2FA, making sure losing one ≠ losing all accounts is a big step.

