Opnsense firewall at perimeter...and that's about it. Chances of anything getting in with no exposed ports is pretty slim so I don't really bother with anything more.
For SSH exposed servers/VPS I do change the port though. Cut down log noise & maybe dodge the odd portscanner or two
The one is bits the other is bytes ;)
Network...3 gigabits, while a decent nvme gen 4 can do 4-5 gigabytes
Even old SATA connected SSDs should be able to keep up if you don't buy trash.