Individuals and organisations should use strong passwords, enable 2FA wherever possible, keep devices updated, watch for suspicious emails even from known contacts, enable email scanning from providers, and monitor settings for suspicious mail forwarding rules.