Skip to main content
.com domains from $2.99 — WHOIS privacy at no extra charge

How-to · Advanced · one hour

How to Secure a New VPS

The first hour of hardening that heads off almost every compromise — a practical, jargon-free walkthrough with the classic mistake flagged before you make it.

Straight answer first

In a line: the first hour of hardening that heads off almost every compromise — a advanced-level task that takes one hour.

The walkthrough below covers every step, the mistake most people make, and the shortcut worth keeping. On Hosting Seller plans several of these steps are already done for you, and we say where.

Written by the Hosting Seller staff · Checked 1 August 2026

Advanced

Skill needed

5

Stages to finish

Free

Help included

Tested

On our own kit

You do not need to be technical for this. The walkthrough is written for first-timers, tested on our own platform, and honest about which parts are genuinely fiddly and which are merely unfamiliar.

Rule of the road: read the snag section before you begin rather than after. It is harvested from the tickets of people who did it the other way round.

The shape of the work

From start to finish, you will patch everything before anything else, lock ssh down, put the firewall up, add fail2ban and turn on unattended security updates.

No stage needs code or a terminal unless the guide says so outright, and where it does, the exact commands are printed. The full step-by-step sits below; the sections around it give the context that makes it stick.

Where this goes wrong, and how not to

Leaving hardening until 'after setup'. Internet-wide scanners find a new server within hours of boot, so the default-configured week between provisioning and hardening is the riskiest period that machine will ever live through.

It is worth learning because it is not some rare edge case — it is the single most common reason this task turns into a support ticket. Knowing it up front turns the whole job from risky into routine.

The tip we hand out to everybody

Write the hardening down as a script or a checklist the first time you do it. Every future VPS then gets the same first hour in about five minutes, and consistency is itself a security property.

It costs a minute now and pays that back every time the job comes round again — which, like most hosting jobs, it certainly will.

The parts we have already done for you

We have automated the steps that do not deserve your time: certificates issue and reissue themselves, the installer handles application setup, the daily backup covers the what-if, and per-site settings live in a panel instead of a config file. The guide above covers what remains — the part that is actually about your site.

And when a step misbehaves anyway, support answers at any hour with the actual fix, not a knowledge-base link and a shrug. Half our best guides began life as a pattern in the ticket queue.

A shield icon standing in for site security and DDoS filtering

A good platform makes every guide shorter

Tutorials age badly when they are written against imaginary hosting. These are written against ours: the same panel, the same installer and the same defaults you will meet.

SSL comes free with every plan and reissues itself before it lapses, so nobody has to diary the padlock.

  • Step by step, tested exactly as printed
  • The snag flagged before you reach it
  • The dull steps are already automated
  • People on hand at any hour if you stall

Why Hosting Seller

On every plan, as standard

The snag, named early

The classic mistake for this exact job is flagged before step one, so one hour stays one hour.

5 steps, no filler

Each stage is a few minutes of steady clicking, with the fiddly parts marked as fiddly.

No jargon toll

Terms are explained where they appear or linked to the glossary — nothing assumes you already know.

Automation where it belongs

SSL, backups and installs run themselves here, so the guide covers only what is genuinely yours to do.

Works exactly as written

Every step tested on the platform we run — no 'your host may differ' hand-waving anywhere.

The undo is always named

Where a step could bite, the guide says so and tells you how to put it back again.

First Steps

From choosing to live

  1. 1

    Patch everything before anything else

    A full package upgrade on first login. The provisioned image predates today's patches, and that gap is precisely what the scanners are out there probing for.

  2. 2

    Lock SSH down

    Key-only authentication, root login disabled, a sudo user for the work. Those three together end the credential-guessing game permanently.

  3. 3

    Put the firewall up

    Default-deny inbound with explicit allows for SSH and the web ports, via ufw or firewalld. Every service you did not list becomes unreachable by default.

  4. 4

    Add fail2ban

    fail2ban bans addresses that keep failing authentication. It is a log-noise reducer and a slow-attack breaker in the same small package.

  5. 5

    Turn on unattended security updates

    Unattended-upgrades for the security channel. That is your always-on baseline for the weeks when the server is nowhere near front of mind.

In the Box

Packed with every plan

  • A 99.9% uptime commitment, watched by monitoring day and night
  • A free SSL certificate on every plan, reissued before it lapses
  • WordPress Toolkit, with updates applied for you
  • PHP versions picked per site from the panel
  • SSH, Git and Composer on the plans built for developers
  • A backup taken daily, with restores you run yourself
  • WebP image optimisation built in and costing nothing
  • Mailboxes that carry your own domain name
  • A 30-day money-back guarantee on every hosting plan
  • Nothing added at setup — no joining fee, ever

Across the Counter

The questions we get asked most

Would anybody bother attacking my small server?

Constantly, and impersonally. Automated scanning targets addresses, not reputations, and every public address gets the same probing within hours of going live. Because the attacks are mechanical, the mechanical basics stop very nearly all of them.

What upkeep does it need after that first hour?

Weekly-ish attention to patches, automated for the security channel, an occasional look at the logs, and backup verification. Call it an hour a month for a stable server — the first-hour hardening is what buys that quiet.

Who actually runs the company?

Hosting Seller is a trading name of Bohzo Ltd, a company registered in England and Wales — a real business with a public record and terms published under English law. Looking that up is worth doing about any host before you hand over your domain.

Which control panel comes with the account?

cPanel, which the whole trade already knows. That means every tutorial online matches what you see, your backups restore onto any cPanel host anywhere, and what you learn here stays useful for life. Plesk and DirectAdmin are stocked on specific plans for anyone who prefers them.

Are backups included, and can I put one back myself?

A backup is taken daily on every plan, and the restore is yours to run from the panel in minutes — files, databases or both, at three in the morning without waiting on a ticket. Keeping your own copy offsite as well is never a bad habit, and nothing here stops you.

How do I read the mail when I am away from the desk?

Webmail opens in any browser, and every mailbox also speaks IMAP, POP and SMTP — so the mail app on your phone, the client on your desktop and webmail all show the same messages in the same order.

What uptime do you commit to, and who is watching?

We commit to 99.9% uptime and watch it continuously. That figure is an operational target rather than a poster line, and the alerting behind it usually has an engineer on a problem before the first customer notices anything is wrong.

Packing up and moving host? Take our checklist.

A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.

One email carrying the checklist, then the odd note on running a site well. Step off the list whenever you like — our privacy policy spells out the rest.

Do the launch properly this time.

From a first website to a rack of servers, moving up is a change to your account rather than a migration.

See the plans