As a little contrast to a list of security technologies...
You can spend all day and all night forever looking at different technical lock-downs and measures to take, but it's often looking at the problem with the wrong end of the telescope once you're past the basics.
My advice is:
1) Work out what risks you're concerned about.
2) To do 1) you need to have a think about what information and services you need to protect.
3) To to 2) you'll need to think about why you want or need to protect these things - e.g. because you need them to run your business, the law requires it, the risk of reputational damage etc.
4) Prioritise the risks (often it can be helpful to use a scoring system which might look something like Risk Level x Impact = Score. Risk Level is how likely (e.g. 1-5) the risk is to happen and Impact is how big a deal it is if it happens (again, say 1-5).
You can look up risk assessment if you want and make it more complex, but in a nutshell this will do and you're just trying to get some perspective on what to worry about most and crucially, where you should spend money.
This may sound like a massive faff compared to asking for some recommendations and doing the ones like the sound of, but it changes it from being a technical problem to a business one.
If you don't do something like the above, you can spend fortunes and still miss the most important things.
Simplifying a little...
Things like Cyberessentials bundle up basic security measures that the majority of businesses should consider and essential security knowledge. It's an attempt to simplify doing
something about security
. Worthwhile if you don't know where to start, but don't get a false sense of....well, you know.
When you go through the steps set out above, consider a broad set of risks because when the stuff hits the fan, it doesn't matter whether it was some super clever DDoS attack from the other side of the world or the cleaner unplugging your server, the impact's the same.
Other advantages of the approach I recommend:
a) If you go through the above, you should be in a much better position to determine how much time and money to throw at the problem. On the one hand it will always be tempting to think that it's money spent on nothing (like insurance right

?) On the other hand there will be plenty of security specialists who will give all sorts of dire warnings about how you need to do everything under the Sun. Neither's right unless tailored to your business (and the stage of your business).
b) You may work out that you have enough valuable information and services at risk that you want to get some paid help form a specialist to help with some of the assessment above and selection of security measures.
c) You'll need to consider the non-technical risks before getting to technical "solutions" e.g. employees/contractors accessing customer data not just external cyber attack.
d) You may be able to find a non-technical workarounds before you get to technical "solutions". - e.g. a (now trivial) example would be with credit card data - many ecommerce businesses now avoid the risk of holding credit card data altogether by using a payment processor. Another would be staff background checking and limiting access to data.
None of the above is meant to suggest that technical solutions for security are no good or not needed. There is a whole industry for security products and services whose marketing puts these uppermost in our minds. The reality is that addressing security in a business-like and effective fashion is about more than checklists.