What to do before anything else.
THE ORDER THAT MATTERS
Secure it before you use it.
STEP ONE: UPDATE EVERYTHING
Apply all available system updates immediately.
A new image is frequently weeks or months old.
STEP TWO: CHANGE DEFAULT CREDENTIALS
Any default password. Immediately.
STEP THREE: CREATE A NON-ROOT USER
Work as that user. Use elevated privileges only when needed.
STEP FOUR: SET UP KEY-BASED LOGIN
Then disable password authentication for remote access.
That single change eliminates the most common attack.
STEP FIVE: CONFIGURE THE FIREWALL
Allow only what you need. Deny everything else.
STEP SIX: SET UP BACKUPS
Before you have anything worth losing.
STEP SEVEN: SET UP MONITORING
So you know when something is wrong.
WHY THIS ORDER
A server exposed before it is secured is scanned and attacked within minutes of being online.
That is not an exaggeration.