Some Ideas of Security measurements (mostly going further than what you asked for)
The whole Infrastructure is behind OPNSense HA gateways, they run VPN and guest proxy/ reverse proxy. Servers use apt proxy, maybe your own mirror but this is mostly overkill for security reasons.
DNSSEC is also...