So even if the exchange has good security, if our email is not properly secured, there is only so much the exchange can do to protect us. For me, using a different password for your email and exchange is really a must, and if there is 2FA available we should activate it.
The security of our emails should be our responsibility; the exchange cannot do anything about hacked emails, but I am wondering how scammers gain access to emails easily. Do they attempt changing passwords of the mail so that when they gain access to the mail, they go further to check the email inbox and know the exchanges the users are using? If yes, then we need external security to be added to secure our emails, if possible, 2FA for the emails because some of us save some sensitive information in the email.
If we can add extra security to our emails, our exchange accounts are almost safe even without 2FA, but we should add the 2FA for external security.
Above all, it is not encouraged to save your Bitcoin in an exchange; your 2FA will not save your Bitcoin if the exchange is being hacked. Learn to keep self-custody of your Bitcoin and stop relying on exchanges to help you out.