Then I will help them go to cold storage. Then to airgapped devices.
If you are using an air-gapped device, then your funds are in cold storage, the two aren't different in that way, though air-gapped wallets isn't the only type of cold storage, when you use hardware wallets your funds are in cold storage too; funds are in cold storage when the seed phrase and keys are generated and stored offline and would never be connected to the internet.
Step-by-step I will eventually teach them what passphrases do and I will ask them to create a new wallet.
~~~
Them multisig.
Multisig and passphrases are very good extra layers of security, but for people just coming out of exchanges, i think what they need to learn importantly right now is self custody, hot and cold wallets, get them a good self custody wallet like Electrum, next, if their money is small and for fast spending, they can run Electrum on their online device, if they have a large sum and are holding it for the long term, then they should run Electrum on an air-gapped device, or for ease, they should buy a hardware wallet. Multisig and passphrases mean more backups, and it may be complicated for newbies to keep the backups safe, so with more experience they can add more layers of security later on.