Setting up a second factor protected who could change your organisation's settings. It did not protect the two places where reading is itself the sensitive act: the documents attached to your operations, and the edit history recording who changed what.
Both now require the second step, as do the links saying which document belongs to which call — knowing that a class certificate is attached to a particular vessel already reveals much of what the certificate says.
The movements board deliberately does not require it. A port runs around the clock on shared handhelds, and a duty officer who cannot see the board because their session dropped a level is not more secure — they are unable to work, and the predictable response is to stop using two-step sign-in altogether. Moment-to-moment operational work stays reachable; investigating what happened afterwards does not.
If you have not set up a second factor, nothing about your sign-in changes.