Know what you are responsible for
Keep an inventory of applications, account owners and the data each system handles. Identify who can approve access and who responds when something looks wrong. Unknown ownership makes even a small incident harder to resolve.
Keep routine work routine
Use supported authentication controls, maintain dependencies and review permissions when roles change. Follow vendor guidance for the systems you use. Keep credentials out of source code and general project notes.
Practice recovery
Document backups, restoration steps and an escalation contact. Test recovery in a safe environment and record the result. OWASP provides a useful starting point for discussing application risks, but a checklist is not a complete security assessment.