If Lynis list the following suggestion:
Default umask in /etc/profile could be more strict like 027 [test:AUTH-9328]
You will fix it by editing the file /etc/login.defs
and changing the following line from 022 to 027:
1
UMASK 027
(Was at line 151 for me)