Some best practices:
1. keep all software on local machines up to date, and make sure you run virus scanners. many of today's malware will infect your machine so that it can do things like grab your Filezilla XML for a larger botnet.
2. keep all software on remote machines up to date, and use malware scanners. I can't tell you how many times people get hacked from having outdated WordPress plugins etc.
3. if you are small, services like sucuri.net are great for basic malware scanning and removal.
4. have some sort of HR policy regarding passwords and security. things like if someone gets fired, removing their email address and changing their passwords.
that's what I've got off the top of my head!