2FA on email addresses is a must if you're like most people and use email or SMS (text) for your 2FA. For any personal, health, or financial information app/website where you have an account even if don't have 2FA, at least check what methods can be used to verify you. It's possible you have some old phone numbers or email addresses you forgot about still attached. Many people think the words like 'backdoor' refers to some designed hole in the software that lets an attacker access without being seen. While those are legitimate, often 'backdoors' are simply old phone numbers and email addresses that attackers realize aren't in use anymore, but find in leaked data. Then they have all the time in the world trying to gain access to those without anyone noticing.
And while Iran might be looking to step up some attacks, that just makes China delighted that the spotlight on them might fade or point elsewhere for a bit. I don't think people truly realize how much China already has infiltrated enterprise and government networks within the United States, probably mostly due to the fact that they aren't infiltrating to cause pain (at least right now) but rather they just keep on trying to dig deeper and learn how we handle it.
In short, use this opportunity Edman is pointing out to lower your attack surface, but understand the risk will remain even after this Iran situation cools down.