Defense in Depth. I have 4 networks, Home, Testing, Production, Production DMZ. At each layer I use firewalls and NIPS devices. Production and Testing have a SOAR appliance tied to Zeek NDR.
I have a robust maintenance schedule with checks and security patches installed ever 2 weeks. I have everything documented, services are run in their own containers instead of on monolithic servers.
Every system and component are hardened with modified DISA STIGs. Accounts have only the access they need, and everything is well documented for continuity of Operations.








Ah, the mythical 6th website: Full of screenshots of its fucking self.