I’m not an expert, but just a few personal guidelines off the top of my head:
1) Only store what you absolutely need, you can’t lose what you don’t have
2) When logging, redact passwords and PII
3) Ensure proper user rights using a whitelist (not a blacklist)
4) Use a proper IDS to detect anomalies early