For a small/medium business it is very easy to be overwhelmed in Infosec.
Similar to step 1 in the 12 step AA program. First need to define the honest truth of your environment. Create a baseline of where you are at now, map for improvement and create goals.
Slowly document and start to tune and make changes. Small things can make a huge difference.
Scenario Based Events
As things happen classify and assign severity levels. This way you can go back to future incident and priority reporting.
Most importantly “Don’t Give Up”! Your security posture matters. Hire help with Managed Security Services or get additional staff and tackle your missions!