Places I had to access that stored things as high security required 3 things to access the system.
1 - you had to be marked as present at the front desk. If someone tried to access the account, for example at night or after hours, days you were not supposed to have access, it would be flagged.
2 - Personal smart card inserted in slot at pc - if card was lost/stolen account would be disabled and you could not log off without removing the card first so no forgetting it
3 - personal password
There was also no physical access to any of the hardware. All each user had access to was keyboard with integrated card reader, mouse, monitor. No cdrom, usb, power, or ports. Everything else was behind a locked wire cage under the desk.
The network also had no access to the internet. If you wanted to use the internet to do research or email you left your workstation and went to a pc designed for that task. They were not even going to take the chance that a firewall or some other security appliance could be defeated.
The problem with passwords for the average person though is there are so many of them to remember. When I ask family members what passwords they want to use they almost always give me things like dogs names, birthdays, etc , all the stuff that someone wanting access is going to try first. If I suggest something strong like mixed characters and symbols they get upset.