Design for the realistic threat
Security advice written for large organisations tends to focus on attackers, and it produces controls that a small business cannot maintain. The threat model for a ten person company is different and much more mundane. The customer list leaves with an employee. A shared password is reused on a personal service that gets breached. An integration set up for a trial two years ago still has full access. A phone with every customer conversation on it is lost.
Each of those has a cheap and permanent fix, and none of them requires a security consultant. The checklist below is ordered by how much risk it removes per hour of effort.