(Author here.) Well, you could always use this questionnaire as a starting point itself: ask yourself these questions, and if you're not happy with the answers, do something about it.
Another reasonable security practices starting point would be another article by Latacora: https://latacora.micro.blog/2020/03/12/the-soc-starting.html
It's semi-oriented towards SOC2, but every item on that list is practical, doable even for small teams, and has real solid security impact.