Well, one issue is even if MFA is easy to implement, unless the rest of your site is appropriately set up, a hacker could still bypass it. I know one site where someone was able to completely bypass the 2FA and other login protections because they figured out how to get ahold of an admin's session token from a database hack.
I wouldn't be surprised if this was on their list of to dos already, but my guess is it's not going to happen until some of their other system overhauls get finished.