There's a concept called "security awareness" that the InfoSec experts talk about a lot. It's basic course in staying safe online and, well, in the case of companies, keeping the company safe as well. You might want to consider running through some of that curriculum. I don't get the feeling it's long and arduous to get through but it has been shown to help. It's far from full proof because people can still make mistakes but it helps.

Also, of course, there are the usual things you can do to make their computing/networking environment more secure, which I'm sure other commenters have mentioned.

Note: You will quickly find examples of what's taught with a web search. You could do a stripped down version very quickly.

