Hass.io Security

Hi,
Would anybody have any recomendations for what security system we should have in place for our hass.io instance. Our hass.io instance has to be exposed to the internet but i could only allow the services that i need, sadly all i have is the BT home hub 5

Tor is recommended

There’s at least a couple of threads on security already, worth a read of those (and obviously the official documentation)