Couple notes: * VPNs are not panacea. My own experience is that ssh and significant key management (no password or emergency password only) is a more scalable strategy than relying solely on VPNs for small business. The whole default port thing with ssh is a no-brainer (don't do it + restrictive configurations of ssh for port forwarding and tunneling) as are the standard approaches to dealing with abuse of any service (fail2ban, etc...) Add to this a design which sandboxes ssh access based on time/privilege and only allows escape|access to critical resources via another mechanism. * WAFs are great but are extremely high maintenance and can be a productivity and production malf and bottleneck waiting to happen. * DDOS mitigation: https://www.akamai.com/us/en/solutions/products/cloud-securi... or the like.