Create a immutable, WORM-Like Network-Share that holds REALLY!!! sensitive data like desaster-recovery-plans, password databases, network-plans, all the data you need in worst case and that should not be encrypted by any ransomware.
When ransomware locks down your systems, this is your machine to go, plug in a console and start recovery.
When sealing the vault, you can not access it over ssh any more so no ransomware can access the system.
You should NOT NOT NOT NOT have a KVM-Console connected because this can be used to access the system over the network