I would suggest that the effort you're asking for is already going in to
Debian itself, and that together the maintainers deliver a system that
is a reasonable compromise between security and convenience for a
general use personal computer. People who want to go beyond that and
offer a public service really do need to be expected to learn the
vulnerabilities and vectors that apply to the type of service they're
running.
There is no blanket security policy that would be able to apply the
correct security for every circumstance. Believe me, you wouldn't enjoy
running a fully PCI/DOC secured system as your daily driver.
--
Jonathan