The ones that cause real damage.
NOT SECURING IT BEFORE GOING LIVE
Automated attacks find new servers within minutes. Secure first, deploy second.
LEAVING PASSWORD AUTHENTICATION ENABLED
Brute-force attacks run continuously against every server. Keys eliminate the risk entirely.
NOT APPLYING UPDATES
The single most common route to compromise. The patch existed; nobody applied it.
DEFERRING REBOOTS AFTER KERNEL UPDATES
The patch is installed and not in effect. Months of false security.
NO BACKUPS, OR UNTESTED ONES
Discovered during an emergency, which is the worst possible time.
BACKUPS STORED ON THE SAME SERVER
Lost in the same event that loses the server.
EXPOSING THE DATABASE
Scanners find open database ports within hours.
RUNNING EVERYTHING AS ROOT
One application vulnerability becomes total compromise.
NO MONITORING
The site is down and you find out from a customer.
NO DOCUMENTATION
Rebuilding becomes archaeology.
BUYING UNMANAGED WITHOUT THE SKILLS
The most expensive mistake, because it produces all of the above.