Team safety: where most breaches start
The organizational base
A password manager for everyone, two-factor on every service that supports it, disk encryption on laptops, and automatic system updates.
An orderly joining-and-leaving process: who gets access to what, and who verifies it's all closed on the day of departure. Accounts of departed employees are an especially common vector.
Phishing
Most attempts arrive as legitimate-looking email: an urgent transfer request, a password-reset link, a file from accounting. The defense is a procedure, not vigilance: every financial request or change of bank details is verified over a second channel.
Encourage reporting without shame. An employee who reports a mistake within a minute saves a day of investigation.
Forgotten access
Tools signed up for a trial, personal keys in repositories, and file shares open to anyone with the link. Do a periodic review.
Going deeper
Keep a list of every external service in use, who the admin is in each, and what data goes to it. That list is needed in any security incident and any audit, and building the picture during an incident is a critical waste of time.