Hass.io Security

Would anybody have any recomendations for what security system we should have in place for our hass.io instance. Our hass.io instance has to be exposed to the internet but i could only allow the services that i need, sadly all i have is the BT home hub 5

Tor is recommended

There’s at least a couple of threads on security already, worth a read of those (and obviously the official documentation)