Physical security — locked doors, CCTV, keycard access, cable locks for hardware
Staff training — teach all employees to recognise threats, handle data properly, follow security policies
Acceptable Use Policy (AUP) — rules for how company systems may be used; signed by all staff
Regular backups — 3-2-1 rule: 3 copies, 2 different media, 1 offsite. Protects against ransomware and hardware failure.