Haven’t had any issues so far. I don’t like unattended upgrades, so I won’t be doing that. The reminder to check SSH configs is a good one though. I did set up 2FA for web login, etc and set the firewall up.
Backups. I need to get automatic backups going. 😬
We had customers who got cryptolockered and they encrypted the backups as well as the main system. So do something to prevent that.
Hmm. I was looking at an extension to dump backups to S3 compatible storage. I should be able to set up some sort of immutability depending on the vendor I think? 🤔