The businesses I worry about most are never the ones who call me in a panic. They're the ones who never call at all, because nothing bad has happened to them yet.
Most of them have already done the obvious things. Antivirus, a firewall, maybe multifactor authentication if their provider pushed hard enough. Some of them have already read what a layered defense is supposed to look like and checked every box on the list. We covered that list in an earlier post: network protection, endpoint security, email filtering, multifactor authentication, backup and recovery, user training, monitoring. If you haven't read that piece, it's worth a look, because everything below assumes you already have those layers or are working on them.