How-to · Advanced · one hour
How to Secure a New VPS
The first hour of hardening that heads off almost every compromise — a practical, jargon-free walkthrough with the classic mistake flagged before you make it.
Straight answer first
In a line: the first hour of hardening that heads off almost every compromise — a advanced-level task that takes one hour.
The walkthrough below covers every step, the mistake most people make, and the shortcut worth keeping. On Hosting Seller plans several of these steps are already done for you, and we say where.
Written by the Hosting Seller staff · Checked 1 August 2026
Advanced
Skill needed
5
Stages to finish
Free
Help included
Tested
On our own kit
You do not need to be technical for this. The walkthrough is written for first-timers, tested on our own platform, and honest about which parts are genuinely fiddly and which are merely unfamiliar.
Rule of the road: read the snag section before you begin rather than after. It is harvested from the tickets of people who did it the other way round.
The shape of the work
From start to finish, you will patch everything before anything else, lock ssh down, put the firewall up, add fail2ban and turn on unattended security updates.
No stage needs code or a terminal unless the guide says so outright, and where it does, the exact commands are printed. The full step-by-step sits below; the sections around it give the context that makes it stick.
Where this goes wrong, and how not to
Leaving hardening until 'after setup'. Internet-wide scanners find a new server within hours of boot, so the default-configured week between provisioning and hardening is the riskiest period that machine will ever live through.
It is worth learning because it is not some rare edge case — it is the single most common reason this task turns into a support ticket. Knowing it up front turns the whole job from risky into routine.
The tip we hand out to everybody
Write the hardening down as a script or a checklist the first time you do it. Every future VPS then gets the same first hour in about five minutes, and consistency is itself a security property.
It costs a minute now and pays that back every time the job comes round again — which, like most hosting jobs, it certainly will.
The parts we have already done for you
We have automated the steps that do not deserve your time: certificates issue and reissue themselves, the installer handles application setup, the daily backup covers the what-if, and per-site settings live in a panel instead of a config file. The guide above covers what remains — the part that is actually about your site.
And when a step misbehaves anyway, support answers at any hour with the actual fix, not a knowledge-base link and a shrug. Half our best guides began life as a pattern in the ticket queue.

A good platform makes every guide shorter
Tutorials age badly when they are written against imaginary hosting. These are written against ours: the same panel, the same installer and the same defaults you will meet.
SSL comes free with every plan and reissues itself before it lapses, so nobody has to diary the padlock.
- Step by step, tested exactly as printed
- The snag flagged before you reach it
- The dull steps are already automated
- People on hand at any hour if you stall
Why Hosting Seller
On every plan, as standard
The snag, named early
The classic mistake for this exact job is flagged before step one, so one hour stays one hour.
5 steps, no filler
Each stage is a few minutes of steady clicking, with the fiddly parts marked as fiddly.
No jargon toll
Terms are explained where they appear or linked to the glossary — nothing assumes you already know.
Automation where it belongs
SSL, backups and installs run themselves here, so the guide covers only what is genuinely yours to do.
Works exactly as written
Every step tested on the platform we run — no 'your host may differ' hand-waving anywhere.
The undo is always named
Where a step could bite, the guide says so and tells you how to put it back again.
First Steps
From choosing to live
- 1
Patch everything before anything else
A full package upgrade on first login. The provisioned image predates today's patches, and that gap is precisely what the scanners are out there probing for.
- 2
Lock SSH down
Key-only authentication, root login disabled, a sudo user for the work. Those three together end the credential-guessing game permanently.
- 3
Put the firewall up
Default-deny inbound with explicit allows for SSH and the web ports, via ufw or firewalld. Every service you did not list becomes unreachable by default.
- 4
Add fail2ban
fail2ban bans addresses that keep failing authentication. It is a log-noise reducer and a slow-attack breaker in the same small package.
- 5
Turn on unattended security updates
Unattended-upgrades for the security channel. That is your always-on baseline for the weeks when the server is nowhere near front of mind.
In the Box
Packed with every plan
- A 99.9% uptime commitment, watched by monitoring day and night
- A free SSL certificate on every plan, reissued before it lapses
- WordPress Toolkit, with updates applied for you
- PHP versions picked per site from the panel
- SSH, Git and Composer on the plans built for developers
- A backup taken daily, with restores you run yourself
- WebP image optimisation built in and costing nothing
- Mailboxes that carry your own domain name
- A 30-day money-back guarantee on every hosting plan
- Nothing added at setup — no joining fee, ever
Across the Counter
The questions we get asked most
Would anybody bother attacking my small server?
Constantly, and impersonally. Automated scanning targets addresses, not reputations, and every public address gets the same probing within hours of going live. Because the attacks are mechanical, the mechanical basics stop very nearly all of them.
What upkeep does it need after that first hour?
Weekly-ish attention to patches, automated for the security channel, an occasional look at the logs, and backup verification. Call it an hour a month for a stable server — the first-hour hardening is what buys that quiet.
Who actually runs the company?
Hosting Seller is a trading name of Bohzo Ltd, a company registered in England and Wales — a real business with a public record and terms published under English law. Looking that up is worth doing about any host before you hand over your domain.
Which control panel comes with the account?
cPanel, which the whole trade already knows. That means every tutorial online matches what you see, your backups restore onto any cPanel host anywhere, and what you learn here stays useful for life. Plesk and DirectAdmin are stocked on specific plans for anyone who prefers them.
Are backups included, and can I put one back myself?
A backup is taken daily on every plan, and the restore is yours to run from the panel in minutes — files, databases or both, at three in the morning without waiting on a ticket. Keeping your own copy offsite as well is never a bad habit, and nothing here stops you.
How do I read the mail when I am away from the desk?
Webmail opens in any browser, and every mailbox also speaks IMAP, POP and SMTP — so the mail app on your phone, the client on your desktop and webmail all show the same messages in the same order.
What uptime do you commit to, and who is watching?
We commit to 99.9% uptime and watch it continuously. That figure is an operational target rather than a poster line, and the alerting behind it usually has an engineer on a problem before the first customer notices anything is wrong.
Read next
How to Free Up Mailbox Storage
Get space back before senders start receiving bounce messages — beginner level, about 30 minutes.
How to Back Up WordPress
Hold backups that exist, restore cleanly, and survive the day you need them — beginner level, about 30 minutes of setup.
Domain Names
Search, register and transfer names — year one free with annual hosting.
cPanel Reseller Hosting
The panel the trade already knows, sized for resellers, WHM in the box.
Packing up and moving host? Take our checklist.
A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.
Do the launch properly this time.
From a first website to a rack of servers, moving up is a change to your account rather than a migration.
See the plans