A fresh VPS is exposed to the whole internet from minute one. Here are the first security steps to take after you deploy.
Bots start probing a new server within minutes. To secure a Linux VPS, lock down access, patch it, and put a firewall in front before you do anything else. Here's the order to do it in.
Use SSH keys and disable password login
Set up SSH key authentication and turn off password logins entirely. Keys are far harder to brute-force than passwords and stop the most common automated attacks dead.
Disable root login and create a sudo user
Log in as a normal user with sudo rather than root. It limits the damage if an account is ever compromised and removes the obvious 'root' target attackers hammer.
Set up a firewall and keep it updated
Allow only the ports you actually use (SSH, HTTP, HTTPS) with a firewall like UFW, and apply security updates promptly. Out-of-date software is the top way servers get breached, see protecting your website from hackers.
Add fail2ban and back up
Install fail2ban to auto-block repeated failed logins, and set up off-site backups so you can recover fast. Prefer not to manage all this? A managed VPS keeps it hardened and patched for you.
Key takeaways
- Use SSH keys; disable password logins.
- Disable root; use a sudo user instead.
- Run a firewall and patch promptly.
- Add fail2ban and off-site backups.
Prefer a managed, secured VPS?
Gander Web can harden, patch and monitor your UK Ryzen VPS so you can focus on your business.
See managed VPS hostingFrequently asked questions
What's the first thing to do on a new VPS?
Set up SSH keys, disable password and root login, update the system, and enable a firewall, before hosting anything on it.
Do I need a firewall on a VPS?
Yes. A firewall that allows only the ports you use blocks a huge amount of automated probing and attacks.
Can someone else secure my VPS for me?
Yes. A managed VPS includes hardening, updates and monitoring so you don't have to do it yourself.