The summary.
REDUNDANCY MUST BE GENUINELY DIVERSE
Two cables in one tray, two connections to one switch, two providers on one fibre route, or both switches on one power feed — none of those is redundancy.
That last one is commonly overlooked and makes switch redundancy meaningless.
TEST FAILOVER DELIBERATELY
Configurations that should fail over frequently do not, and nobody discovers it until it matters.
ALERT ON LOSS OF REDUNDANCY, NOT ONLY LOSS OF SERVICE
Running on a single path after a silent failure is a common and dangerous state.
RISING ERROR RATES PRECEDE FAILURE
A link passing traffic with rising errors is failing quietly, and degrades performance before anything appears down.
NEVER EXPOSE MANAGEMENT INTERFACES TO THE INTERNET
They provide complete control of a server, and anything reachable is found by scanning within hours.
VOLUMETRIC ATTACKS CANNOT BE DEFENDED AT YOUR OWN SERVER
Mitigation must happen upstream. Establish what your provider offers, and how quickly it engages, before you need it.
OUTBOUND TRANSFER IS USUALLY THE CHARGED AND EXPENSIVE DIRECTION
Back up device configurations, and test that one can actually restore a device.