1) Strong Prevention (Make leaks harder and less likely)
Account & Access Hygiene
Use a unique password per service + a password manager (1Password, Bitwarden, etc.).
Enforce two-factor authentication (2FA) on every account (authenticator apps preferred over SMS).
Limit admin access: only give...