Basic VPS Security: A 10-Point Checklist
VPS and servers Published: 31.03.2026 · 5 min read
Most breaches happen not because of clever vulnerabilities but because of an “admin123” password and a port left open to the internet. Ten simple steps close off the bulk of the risk.
1. Change the port and disable root password login
Automated scanners brute-force SSH and RDP passwords on standard ports around the clock. Key-based login instead of a password closes this attack vector completely.
2. Create a separate user
Work under a regular account and elevate privileges only when needed, rather than staying logged in as administrator all the time.
3. Configure a firewall
The rule is simple: block everything except what genuinely needs to be reachable from outside. Typically that’s ports 80 and 443 for a website and a remote access port restricted by IP.
4. Enable brute-force protection
Fail2ban or an equivalent: after several failed login attempts, the address is blocked automatically.
5. Keep the system updated
Most successful attacks exploit vulnerabilities that were patched months ago. Turn on automatic security updates.
6. Check what’s exposed
Databases, control panels and test interfaces often end up reachable from the internet by oversight. Scan your own IP and see what responds.
7. Set up backups before you need them
Backups must be stored separately from the server. Ransomware that gets onto the machine will encrypt local backups too.
8. Take a snapshot before making changes
A one-minute habit that saves hours of recovery.
9. Keep an eye on the logs
A regular look at login logs reveals password-guessing attempts and suspicious activity long before serious consequences.
10. Limit application privileges
The web server and the database shouldn’t run as administrator. Give each service only the minimum privileges it needs.
If your team has no system administrator, write to us: we’ll point out what’s critical for your particular configuration.
We’ll pick a configuration, calculate the cost and migrate your project for free.