DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk5 min

How to Secure a VPS: Essential Steps for Beginners

A practical beginner baseline for securing a new Linux VPS: protect provider access, set up tested SSH keys, limit network exposure, update software, and prepare for recovery.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To secure a new VPS, protect your hosting account, administer the server through a named non-root account, use SSH keys, limit inbound connections to the services you need, install security updates, and prepare backups and a recovery route. Then secure the applications you actually run. These steps are a practical baseline—not a guarantee of security for every workload. Commands and settings vary by Linux distribution and release, provider, and installed services.

What to do first after creating a VPS

VPS security is shared work: the provider protects its infrastructure, while you are responsible for the data and configuration on your instance. DigitalOcean describes this division for Droplets in its shared responsibility model. Begin with your provider account, because an attacker with account access may be able to affect the server itself.

As an Amazon Associate I earn from qualifying purchases.

  1. Protect the hosting account. Use a unique password, enable the provider’s multifactor authentication (MFA), and review which people or accounts can manage your VPS. DigitalOcean recommends protecting account credentials, using individual user accounts, and enabling two-factor authentication by default in its Droplet shared-responsibility guidance. If you are considering a FIDO2 security key, first confirm that your provider supports it.
  2. Establish a recovery route. Find out how to reach the provider’s web console or other recovery mechanism before changing SSH settings. The available method depends on the host. Keep access to the provider account itself secure.
  3. Create a named administrator. Avoid routine work as root. Use a personal, non-root account with only the privileges needed, and use sudo for administrative tasks. Ubuntu’s security suggestions describe this least-privilege approach.
  4. Set up SSH key login and test it. DigitalOcean recommends SSH keys over password login and provides instructions for adding keys to new or existing Droplets in its SSH key guide. Confirm that the named account can log in with the key and run the required administrative commands with sudo. Keep your current session open while testing a second login, and make sure the recovery route works.
  5. Only then change SSH login policy. Once key access and recovery are confirmed, disable password-based SSH login and password-based root access if appropriate for your distribution and provider. Follow the provider’s and operating system’s instructions for the exact setting; a misplaced configuration change can lock you out. DigitalOcean’s production-ready Droplet setup recommends key authentication for a sudo non-root user and no password-based access to root.
  6. Allow only the network traffic you need. Start with the minimum inbound access necessary to configure the server. DigitalOcean’s setup example restricts its cloud firewall to SSH during initial configuration; a public website or other service needs the port or ports required by that service. Apply rules at the provider level and, where used, on the host as well. Check IPv4 and IPv6 rules if IPv6 is enabled.
  7. Install security updates. Use the package-management and update guidance for your distribution. Ubuntu recommends keeping software updated and documents unattended upgrades as an option for applying security updates and bug fixes. Check that updates are being applied rather than assuming an automatic-update setting is active. Whether an update requires a reboot depends on the update and workload.
  8. Set up backups and understand restoration. Enable provider backups if available, learn what they include, and identify how to restore them. DigitalOcean recommends automatic Droplet backups in its setup guidance and describes its backup service as system-level backups. A backup is not proven usable for your needs until you have tested a restore in your environment.
  9. Harden the services you run. Remove or avoid software you do not need, and apply the security guidance for each exposed application or service. Ubuntu describes a layered approach and identifies AppArmor as a way to limit software permissions in its server security documentation. There is no single service-hardening checklist that fits every VPS workload.

SSH keys and passwords: what changes—and what does not

With password-based SSH, the server accepts a password as the login proof. With key-based authentication, you configure a public key on the server and use its matching private key to authenticate. DigitalOcean recommends key pairs and explains them in its Droplet security best-practices guide. Keys improve the login method but do not protect a compromised provider account, an exposed private key, or an insecure application. Protect the device and private key you use to connect, and retain a recovery route before tightening SSH access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloud firewalls and host firewalls

A cloud firewall filters traffic at the provider’s network edge; a host firewall filters traffic on the VPS operating system. Ubuntu recommends a firewall as part of server security, while DigitalOcean’s Droplet guidance describes provider-level firewall use. One layer does not universally replace the other. Use the controls available to you and keep their rules consistent with the services that should be reachable.

#1 Best Overall
ZOERAX 100-Pack M6 x 16mm Rack Mount Cage Nuts, Screws and Washers
  • Wide Compatibility & Versatile Use: ZOERAX M6 rack mount screw kit is ideal for installing server racks, network cabinets, rack shelves, patch panels, A/V equipment, and more. Designed for standard square-hole racks and cabinets, these M6 cage nuts and screws ensure a secure fit for most 19-inch rack systems used in data centers, offices, and home labs
  • Heavy-Duty Carbon Steel Construction: Made from premium carbon steel, these M6 cage nuts and screws deliver high strength and long-lasting durability. The material provides excellent resistance to rust, corrosion, and oxidation, performing reliably in demanding environments such as high humidity, temperature fluctuations, and long-term rack installations
  • Precision Metric Standard M6: Manufactured to strict metric standards, each M6 screw and cage nut features precise dimensions with minimal tolerance. Clean, sharp threads without burrs allow smooth installation without stripping or slipping. The deep Phillips head design ensures better torque control and faster, more efficient mounting
  • Safe, Reliable & Eco-Conscious Materials: ZOERAX uses non-toxic, environmentally friendly carbon steel materials to ensure safe handling and use. Heat-treated for optimal hardness, ductility, and impact resistance, these rack screws and cage nuts offer dependable performance while meeting safety and quality expectations for professional installations
  • Complete Mounting Kit with Washers: This essential M6 rack hardware kit includes screws, cage nuts, and heavy-duty washers. The included washers help distribute pressure evenly and reduce scratches or marks on rack rails and equipment, providing a cleaner, more secure installation right out of the box
Control Where filtering happens What to check
Provider or cloud firewall At the hosting provider’s network layer, before traffic reaches the instance. Confirm which addresses and ports are allowed, how rules are managed, and whether rules cover IPv4 and IPv6.
Host firewall, such as Ubuntu’s firewall tools On the VPS operating system. Confirm local rules match the services running on the host and are not unintentionally broader than provider rules.

Do not copy a universal port list without knowing what the VPS does. A web server, database, VPN, and remote administration service have different exposure needs. Allow only the access required for the services you intend to provide, and check both firewall layers after changes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep the baseline effective over time

  • Review updates: Verify that security updates are being installed. Ubuntu documents unattended upgrades as an option; choose settings appropriate to your release and workload.
  • Review exposure: When you add or remove a service, revisit provider and host firewall rules, including IPv6 where enabled.
  • Review access: Remove accounts or keys that no longer need access, and review who can manage the provider account.
  • Review recovery: Know how to restore the backup you have enabled, and test restoration for your environment rather than treating backup status as proof.

For Ubuntu-specific security concepts and controls, consult the current security suggestions and security documentation. For provider-specific setup, use your host’s instructions: the DigitalOcean recommendations cited here apply to Droplets, not automatically to every VPS provider.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.