OWASP recommend to set these HTTP response headers.
  • X-Content-Type-Options
  • Strict-Transport-Security