A short checklist: MFA, backups, least privilege, patching, and monitoring.
Make training short, realistic, and measurable.
Map scope, assess gaps, prioritize controls, and prepare for audit interviews.
Who declares an incident, how comms flow, and when to restore or pay.
Right cadence, right difficulty, and actionable coaching moments.