How to make your Qubes OS more secure (Best Practices)

Since you mentioned Debian and Whonix: I tend to run any Debian-based stuff in a Kicksecure AppVM, which includes the Linux Kernel Runtime Guard.

I do too, but it seems I had to explicitly install it following the
guide linked earlier in this thread. Just did.