Most incidents don't involve anything exotic. They involve an over-permissioned account, an unpatched system, or a backup nobody tested.
Security marketing is dominated by sophisticated threats, which makes the actual work look inadequate by comparison. The actual work is mundane, and it is what stops most incidents.
In rough order of return on effort, here is what matters.
Multi-factor authentication, everywhere it fits
MFA on email, remote access and administrative accounts closes off the single most common path in: a working password obtained through reuse, phishing or a third-party breach.
The objection is friction, which is real but small and one-time. The alternative is that a password from an unrelated site becomes an entry point into your business.
Access that reflects today, not history
Access accumulates. People change roles and keep old permissions; contractors finish and keep accounts; service accounts get created for one integration and outlive it by years.
What breaches typically exploit is not an exotic vulnerability but a legitimate credential with far more reach than the role needs. A quarterly review of who can reach what — and automatic removal when people leave — costs very little and closes a great deal.
Patching, including the third-party layer
Operating system updates are usually handled. Third-party applications — PDF readers, browsers, plugins, line-of-business software — often are not, and that is precisely where attention has moved.
This does not need to be exciting. It needs to be scheduled, tracked, and someone's responsibility.
Backups you have actually restored
Ransomware turns a backup question into an existential one. The organisations that recover quickly are the ones that tested a restore recently; the ones that do not are usually the ones who had backups running and never verified them.
Test a real restore quarterly. Keep at least one copy offline or immutable, because ransomware operators specifically target connected backups.
Knowing what you have
You cannot protect an asset nobody has written down. Most first engagements uncover systems, accounts or data stores that no current employee was tracking.
An inventory of devices, accounts, licences and data locations is unglamorous and underpins everything above it.
A reasonable order
MFA first, because it is the highest return for the lowest effort. Then access review, then patching discipline, then tested backups, with the inventory running alongside.
None of this requires a large budget. It requires it to be someone's actual job — which is the part that usually gets skipped.
