Install updates first
Refresh the package index and install available security updates before deploying public applications. Reboot when a kernel update requires it.
Secure remote access
Use SSH keys, disable password authentication when practical and avoid allowing unnecessary users to log in remotely.
Only expose required ports
Configure a firewall and open only the ports needed by your applications. Keep databases and internal services private whenever possible.
