(0) Get Time Machine configured and running. if you have the budget for it, via NAS with Time Machine support. That NAS gets the backup located further away from the computer. Out of coffee spill range, etc. Otherwise, via locally-connected hard disk storage. Probably 4 to 6 TB, or so.
... {good list, above} ...
(4) Set up mail rules that automatically file all arriving messages with attachments from any unrecognized mail senders as spam. I’d consider setting all mail from unrecognized senders to be treated as spam; for all arriving mail, save for that mail either with addresses in the address book, or previously emailed.
(5) Set up your own admin login, with your own password. This as a means of access if the main accounts are somehow blocked.
(6) Get iCloud Keychain configured for password storage. Because passwords get forgotten. And because iCloud Keychain won’t enter credentials into phishing websites.
(7) In Safari, disable automatically opening of “safe” attachments.