While it is a relatively new (they say alpha-quality) package, the OpenSnitch software suite (https://github.com/evilsocket/opensnitch) offers some value from a security standpoint, by presenting the user with notifications when applications try to make outbound connection requests.
I'd like to suggest we package this for PureOS (with the ultimate goal of upstreaming the project) so we can evaluate whether we'd like to enable something like this by default for users.