Highlights
- Layered brute-force defence: cloud security groups, host UFW/iptables and log-aware bans; VPN/bastion and IP allow-lists.
- Auth hygiene (per-role accounts, key-preferred auth, MFA, audit logging), service-exposure review, WAF-style CVE rules.
- Central auth-log monitoring, brute-force detectors and a rapid triage playbook per alert.