The first hour.
WHAT TO DO FIRST
Update everything.
WHAT NEXT
Create a named account for yourself Add your key Grant it sudo Test logging in with it, in a second session
WHY THE SECOND SESSION
So a mistake does not lock you out while you still have access.
WHAT THEN
Disable password authentication Disable direct root login Restart SSH and confirm you can still connect
WHAT NEXT
Configure the firewall, denying inbound by default Permit only what is needed Confirm access still works
WHAT TO SET
The hostname The time zone, and time synchronisation
WHAT TO INSTALL
Only what the machine is for, plus the diagnostic tools you rely on.
WHAT TO CONFIGURE EARLY
Automatic security updates, where appropriate Log rotation for anything you add Monitoring Backups
WHY BACKUPS EARLY
A machine without them is one incident from total loss, from the first day.
WHAT TO DOCUMENT
Everything you just did.
WHAT TO TEST BEFORE PUTTING IT INTO SERVICE
A reboot, confirming everything returns.
WHY
It is far better to discover a boot problem now.