sv_allowupload 0
sv_allowdownload 0
sv_allowcslua 0
Don't give FTP or RCON access to ANYONE other than yourself. I don't care if you think you trust them. I've seen so many issues of "my co-owner did this" etc etc etc
Don't put your RCON password in your server.cfg file. Put it in your command line, or don't have rcon.
Don't use workshop addons.
Don't use addons at all.. (I know this isn't really realistic.. but just know that anything you didn't make yourself COULD potentially have a backdoor, so only use trusted/vetted addons)
Don't give admin access to anyone you don't trust explicitly.
Don't allow admins things like ulx ent or ulx rcon.
That's about it really. I can't think of anything else.