CISA’s business-focused guidance highlights four priorities: use logging on business systems, back up business data, encrypt business data, and share cyber incident information with CISA. The emphasis is on faster detection, recovery, and coordinated response.
https://www.cisa.gov/resources-tools/resources/level-your-defenses-four-cybersecurity-best-practices-businesses