Protect accounts first
Use unique passwords and multi-factor authentication for email, banking, cloud storage, domain registrars, website administration and payment platforms. Email accounts deserve special attention because password resets for other services often pass through email.
Keep devices supported and updated
Install security updates, remove unused software and replace systems that can no longer run supported operating systems. Limit administrator privileges for normal daily work.
Assume someone will click a phishing link
Train staff to verify unusual payment, password-reset and file-sharing requests using a second communication channel. Technical controls help, but a clear verification process can stop many business-email compromise attempts.
Prepare for recovery
Maintain tested backups and document who can restore systems, reset accounts and contact important providers. A recovery plan is easier to write before an incident than during one.