(https://www.theregister.com/2020/07/17/ufo_vpn_database/)
So ES has insecure defaults, I get that and it's been discussed to death.
But who the heck, in this day and age, exposes clusters directly to internet traffic? I don't care what the defaults or security measures you have. DONT EXPOSE SERVERS.
Place them inside a VPC, preferably a private one(in AWS parlance, behind a NAT GW). Use _something else_ to send traffic to them. If you are on AWS or similar (but not Azure I guess), add a load balancer to it. So now access would require creating a new load balancer, pointing to the servers in question, adding listeners on the desired ports, and configuring the appropriate security groups. Only then you can send external traffic. On the specific ports you configured on both listeners and security groups only.
Do this everywhere and you are in a much better shape. You still need to configure servers correctly, but if you mess up, nothing happens, unless you mess up many other things in an error cascade.