Ensures recovery after a ransomware or hardware failure (3-2-1 Rule). Fewer running apps mean a smaller "attack surface". Industry Standard Benchmarks
Confirming the OS and applications are on the latest security patches.
Ensuring encryption for data at rest (e.g., S3, EBS) and in transit (TLS/SSL).