* keep your software & dependencies patched
* Disable SSH access for 'root' username.
* If you're using JWTs anywhere, don't mistake them for encryption - they are not.
* Check you're only serving over https.
* Don't trust your frontend. Any security check built into the frontend is near-useless, as the user can reprogram it however they like.
* Strings is how you let the baddies in, especially if you manipulate and concatenate them. Read about SQL injection to find out more.