The incidents we respond to are rarely sophisticated. They are reused passwords, a mailbox without multi-factor authentication, an unpatched device, or a backup nobody had restored from in two years.
Start with identity. Enforce multi-factor authentication everywhere, remove standing administrative rights, and review who still has access after people change roles or leave. Access reviews are dull and disproportionately effective.
Then make patching a routine rather than a project, and protect the endpoint with something that reports centrally so gaps are visible. Segment the network so a compromised device cannot reach everything on it.
Last, treat recovery as a control in its own right. Offline or immutable copies, documented restore steps, and a scheduled test. If you can restore quickly and prove it, most bad days become ordinary ones.
