Skip to main content

Walkthrough · Intermediate · an hour

How to Secure a New VPS

Close the obvious doors in the first hour, before anything is listening in earnest — a hands-on walkthrough in plain words that names the classic mistake before you reach it.

The short answer

One line covers it: close the obvious doors in the first hour, before anything is listening in earnest — a intermediate-level job of roughly an hour.

Below is the full run of steps, the error most people trip over, and the short cut worth remembering. On Hosting & Domains plans several steps are already automated away — the guide marks each one.

By the Hosting & Domains team · Reviewed 18 August 2026

Intermediate

Experience required

5

Stages, start to finish

Free

Support included

Proven

On the platform itself

No technical background needed. This walkthrough was written for first-timers, proven on our own hardware, and honest about which parts are genuinely tricky rather than merely unfamiliar.

First rule: read the snag section before you start, not afterwards. It was distilled from the tickets of everyone who tried the other order.

How the work divides up

Over the whole job, you will patch everything first, create a working user with sudo, lock ssh down, put a firewall in front and add unattended updates and fail2ban.

No part of this needs code or a terminal unless the guide says so plainly — and where it does, the exact commands are printed. The step-by-step is below, with the surrounding sections supplying the context that makes it hold.

Where it comes off, and how to stay on

Leaving a database bound to every interface. Leave MySQL or Postgres listening on 0.0.0.0 behind a weak password and the VPS ends up mining coins for somebody else. Bind it to localhost unless some remote host truly needs access, and have the firewall back that decision up.

It earns a section of its own because it is no obscure edge case — it is the single commonest reason this task reaches a support queue. Knowing it in advance turns the whole job from risky into routine.

What we tell every customer

With the server hardened and the application not yet installed, take a snapshot. That image gives you a clean, known-good point to return to, at far less cost than repeating this hour from memory.

A minute spent now repays itself every time this job comes round again — and like almost every hosting job, come round it will.

The steps already done before you arrive

Steps that never deserved your time are taken out: certificates issue and reissue themselves, the installer handles application setup, the daily copy absorbs the what-ifs, and per-site settings live in a panel rather than a configuration file. The guide covers the remainder — the part that is actually about your site.

Should a step still misfire, support answers at any hour with an actual fix rather than a knowledge-base link and a shrug. Half the guides on this site began as repeat patterns in our ticket queue.

The filtering that absorbs an attack well before it reaches the site

Why this job is shorter on our plans

Every walkthrough in this library is run on the platform we actually operate — cPanel, LiteSpeed, NVMe, one-click installs — so the instructions match your screen rather than gesturing at it from a distance.

The rate you register at is the rate you renew at, so year two costs precisely what year one did — nothing lying in wait on the invoice.

  • Every step checked exactly as published
  • The snag named before it arrives
  • The dull steps taken out of your way
  • People reachable at any hour you stall

Why Hosting & Domains

Standard on every plan

The snag, flagged up front

The classic error for this particular task is named before step one, which is how an hour stays an hour.

5 steps, nothing padded

Each stage is a few minutes of steady clicking, and the fiddly moments are labelled fiddly.

Jargon never charges you

Every term is defined on the spot or linked to the jargon buster — nothing assumes prior knowledge.

The dull parts automated

SSL, backups and installs look after themselves here, leaving the guide to cover only what is genuinely yours.

Works exactly as printed

Every step is proven on the platform we run — none of the 'your host may vary' hedging.

Every undo written out

Any step that could bite is marked, together with the exact way to wind it back.

Quick Start

Order placed to site online

  1. 1

    Patch everything first

    Run the full update before installing a single thing. A fresh image is only as current as the day it was built, and known holes in stale packages are exactly what automated scans look for.

  2. 2

    Create a working user with sudo

    Work as root all day and every typo becomes an incident. Add an ordinary account, give it sudo, move your SSH key across, and keep root for the moments that genuinely need it.

  3. 3

    Lock SSH down

    Keys only, root login disabled, password authentication off. Those three settings remove the entire category of attack that fills an unprotected server's logs within hours of it coming online.

  4. 4

    Put a firewall in front

    Deny inbound by default, then open only what the machine genuinely serves, which on a web host means SSH, 80 and 443. Whatever you never opened is a service the outside world cannot touch.

  5. 5

    Add unattended updates and fail2ban

    Automatic security upgrades keep patches arriving while you are busy, and fail2ban bans the addresses that keep guessing. Between them they cover the two failure modes of a server nobody is actively watching.

Built In

Fitted to every plan

  • Your existing site brought across by our engineers, at no charge
  • cPanel, which is what most of the industry already runs
  • NVMe SSD storage on every tier, not only the dear ones
  • SSH, Git and Composer on the developer plans
  • Free SSL on every plan, reissued before the old one lapses
  • Webmail in the browser plus IMAP, POP and SMTP for any client
  • No set-up charge at any point, and no joining fee
  • PHP versions set per site from the control panel
  • Mailboxes that answer at the name you hold
  • WebP image optimisation built in, at no extra charge

Frequently Asked

The questions that come up most

Is all of this mine to do on a VPS?

A VPS exists to give you root, and administration is part of the bargain. The network, the hypervisor and the DDoS defences are ours to keep healthy, and the operating system sitting on top is yours to run. Where that division is not what you had in mind, managed cPanel hosting puts the entire job back on us.

How often should I go through this again?

Patches want to be automatic and continuous. The rest, meaning open ports, user accounts and who still holds a key, deserves a deliberate look each quarter, because servers drift as projects come and go. A brief reminder that actually recurs beats a thorough audit that never happens.

Who stands behind Hosting & Domains?

Hosting & Domains is a trading name of UK Health Care Support Ltd, registered in England and Wales — a real company with a public filing and terms governed by English law. Running that check on any host before you hand over a domain is time well spent.

Which control panel do accounts use?

cPanel, the panel the industry standardised on long ago. Every tutorial you find online will match what is on your screen, your backups restore onto any other cPanel host, and the skills stay useful for life. Plesk and DirectAdmin are available on particular plans if you prefer either.

Keep reading

Changing hosts? Run through our checklist first.

A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.

What arrives is the checklist, and then the occasional note on keeping a site quick. Leave whenever you like; the privacy policy covers the rest.

Put the site on ground you own.

Free SSL, a free migration, renewals billed at the original rate, and people on support around the clock. That is the whole of it.

View VPS Hosting plans