Good guide. I want to add another point related to Steam log in:
If your steam account is compromised, an attacker can use that to log into your account, bypassing Authenticator. Thus, if you don’t use Steam to play, make sure your steam account is not linked to your OSRS account (check on the osrs website). If you do use steam (does anyone in here?) or want to leave it linked, make sure your steam account follows the same account security principles outlined above, including 2FA through SteamGuard. Finally, if your account has been compromised at any point, make sure to check that a steam account has not been linked to it, as this will allow attackers access even after you recover and “secure” your account.
SoloMission talks about his account being compromised in this way here:
Stay safe guardians!