Things that the average user would be able to do (and should be doing), but wouldn't be so burdensome/onerous that the average user would choose to not do.
2-Factor authentication is an obvious one here. Complex passwords/not reusing passwords would be another.
Things like that?