After they have verified who you are.
Of course it is secure, with 2-factor installed then nobody is getting into your account without the device you've setup to receive the key. If somebody phones up Sony and pretends to be you, they are not suddenly going to be able to get all the details changed.