Same things as on any OS: use strong passwords (or key authentication), stay off shady websites, keep everything up-to-date, turn off anything you don't need. Have services like SSH, FTPS,... listen on a nonstandard port if you wanna go the extra mile and disallow root login. Also install antiviral and antimalware…