Access
Harden SSH, apply MFA where available, constrain sudoers and review accounts.
System
Enable auditd, SELinux or AppArmor, and appropriate ufw or firewalld rules.
Operations
Monitor with Prometheus and Node Exporter, encrypt rsync or Borg backups and test recovery procedures.