One of the things you can do to make a significant difference is configure all of your httpd (apache2, nginx, whatever) to specifically disallow SSLv3, TLS1.0 and TLS1.1.
There is no longer any relevant population of useragents that don't understand TLS1.2.