Go through this list. If you can’t confidently check off every item, that’s where to start.
Multi-factor authentication enabled on every account, not just email
Offsite backups tested in the last 90 days, not just scheduled
A written incident response plan someone other than IT could follow
Endpoint protection on every device, including laptops that leave the office
Local admin rights removed from standard employee accounts
A patch schedule for both servers and workstations, actually followed
Documented, current network diagram less than a year old
Phishing awareness training run at least twice a year