Better IT security starts with an overview
It is easier to keep on top of security when you know which systems you use, who has access and who is responsible for maintenance.

Start with the accounts
Use individual user accounts where possible, unique passwords, and multi-factor authentication where the service supports it. Review access when someone joins, changes role or leaves. Administrator rights should be limited to those who need them.
Agree how updates are handled
PCs, network equipment and software need maintenance. Keep track of what is updated automatically and what needs attention. Plan changes that could interrupt work, and keep documentation and the copies you need.
Check unexpected requests
An urgent message about a payment, a changed account number or a login should be checked through a contact method you already know. Do not use a phone number from the suspicious message as your only confirmation.
Follow up on the backups
Clarify what is backed up, how the copies are protected and who tests that data can be restored. No single setting protects against everything. The aim is several practical measures that are followed up over time.