Also, every quarter or so, schedule an outage, clone the hard drives in the servers to new drives, put the old ones in storage, and run from the clones.
If you have critical hardware that is running some old OS and can't be upgraded, put it on a physically separate network, and data diode, and push those backups out as well.
Test the hell out of those backups, restore something from them at least once a quarter, if not more often.
Start investigating capability based security and operating systems that support that model.
There's multiple points in that chain to address. You'll get the most leverage by reducing domain admin population size through privileged access management.
Tool to help understand the problem: https://github.com/ericalexanderorg/easyhound
Train people not to click on random links.
Have a good intrusion detection system.