you're the one who is supposed to protect your OS from intruders. Hardening a distribution makes it unpleasant experience for users who don't care about hardening and it limits usability in many cases. So ... you can just enable ufw as a start, use only certificate auth for sshd, then move on to deeper hardning, if you need it.



