Security Measures 9200?

Hello Team, you know I already have my doubts about eslasticSearch where I have seen that several pages and companies have stolen all your information just by consulting your endpoint. So what are the security measures that we must establish to avoid this problem and restrict public access or query limits. ??????

First: do not expose elasticsearch to internet
Second: use security feature of elasticsearch (in basic license from 6.8 and 7.1)

