5. Use 2-Factor Authentication where necessary...
It is always necessary. Where there is that feature available, activate it. Of course, don't forget to save the secret code. You'll need it in case your phone is lost or destroyed.
Anyway, many incidents of Bitcoin theft, especially among newbies, is by way of scams posing as investment opportunities. So I guess I would include in the list that beginners should dismiss right away every investment offer coming from ads, social media sites and groups, email, newsletters, random strangers, and so on. That's regardless whether the ROI is too-good-to-be-true or not.