I often say that if an organization doesn't do the first five critical security controls, the other 15 don't really matter.
For an interesting addition to that, Rob Joyce, the head of NSA's Tailored Access Operations (TAO) delivered a rare public talk at the USENIX Enigma conference in 2016. The major takeaway from that is that application whitelisting is that "one thing" that dramatically raises the cost of successfully prosecuting an attack, even for state sponsored actors.
A video of that talk can be found here:
https://www.youtube.com/watch?v=bDJb8WOJYdA
-- wdf//CISSP, CSSLP