← Blog

How to Secure a New VPS: First Steps

September 15, 2026 · 5 min read

A fresh VPS is exposed to the internet the moment it boots. Spending ten minutes on basics keeps out the automated scanners that probe every new server. Here's a practical checklist.

1. Update everything

First thing, always:

apt update && apt upgrade -y

This patches known vulnerabilities right away.

2. Use a strong login

Set a long, unique root password, or better, use SSH keys and disable password login entirely. Keys can't be brute-forced like passwords.

3. Create a non-root user

Working as root all the time is risky. Make a user with sudo:

adduser deploy
usermod -aG sudo deploy

Then log in as that user for day-to-day work.

4. Turn on a firewall

Only expose the ports you actually use:

apt install -y ufw
ufw allow OpenSSH
ufw enable

Add rules for the services you run (for example, 80 and 443 for a website).

5. Consider fail2ban

It watches for repeated failed logins and bans the source IPs — a cheap way to blunt brute-force attempts:

apt install -y fail2ban

6. Keep it patched

Security isn't one-time. Update regularly, and remove software you don't use.

A helpful head start

Some providers let you enable a limited sudo user at deploy time and set an SSH key up front, so the box starts out safer.

Get started

Deploy a server and lock it down in minutes — crypto only, from $10/month.

Ready to deploy?

Fund a balance in crypto and get a server in ~60 seconds.

Get started →