For starters, there are several internationally-accepted best practices and standards for cybersecurity and many companies have implemented all or parts of several of them.
FORBES: Rockefeller Admits Congress Lacks Foundation for Cybersecurity Legislation