A sensible baseline
- Key-based SSH authentication with password login disabled
- A firewall permitting only the ports you actually serve
- Automatic security updates, or a scheduled patching routine
- Malware scanning with automated cleanup
- Off-server backups that are tested by restoring them