By simply converting the following (\"the big 5\"):
& -> & < -> < > -> > \" -> " \' -> '
OWASP has a great cheat sheet.
https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.md