The Reluctant Sysadmin's Guide to Securing a Linux Server
The Reluctant Sysadmin's Guide to Securing a Linux Server
pboyd.io
The Reluctant Sysadmin's Guide to Securing a Linux Server
This guide covers the basics of hardening a new Linux virtual machine when you'd rather be doing something else.

It scratches the surface of the most obvious stuff. I'd only add running apps in isolation (docker or adduser) and maybe fail2ban.