What is the easiest first step my business can take to feel more secure in our IT?

Implement smart password procedures, including a password manager and enabling multi-factor authentication on all accounts, which typically requires something you know (your password) + something you have (usually a text message, email, or app notification).