Those who speak as if security is simple have never done IR.
"Just get a good EDR"
"Just segment your network"
"Just patch"
No. Do all those things, add in shadow IT, hope to god you have a good budget, cry about phishing, & squeeze a lemon in your eye.
This is infosec.


