Reused passwords are the first door. Rolling out a password manager across the organisation closes that door faster than any other technical investment.

Two-factor authentication is not a luxury. Enabling it on email and sensitive systems blocks most login attempts even when a password has leaked.

Phishing keeps evolving: today's messages are well written and carry your organisation's logo. The practical rule is to check the full sender address and never click links that ask for login details.

Backup is the only survival plan against ransomware — provided it is tested regularly. A backup that has never been tested is not a backup.

Finally, security updates for systems and applications cannot be postponed indefinitely; most attacks exploit vulnerabilities that were patched months earlier.