Well... This obviously depends on what you're using the server for.
In terms of SSH, immediately after installing the OS I move it to a non-standard port, require key logins (+ password), setup e-mail alert on SSH Logins (many resources on the internet for that actually! But here's one for...