Skip to main content

10 Essential Steps to Secure a New Linux Server

  • Friday, 5th June, 2026
  • 10:00am

You just deployed a fresh Linux server — congratulations! Before you install anything else, take 15 minutes to lock it down. These ten steps stop the vast majority of automated attacks that hit every public IP within minutes of going online.

1. Update everything first

apt update && apt full-upgrade -y   # Debian/Ubuntu
dnf upgrade -y                        # AlmaLinux/Rocky

2. Create a non-root user

adduser deploy
usermod -aG sudo deploy

Day-to-day work should never happen as root.

3. Switch SSH to key authentication

On your local machine run ssh-keygen -t ed25519, then copy the key with ssh-copy-id deploy@your-server. Test the login before the next step.

4. Disable password login and root SSH

Edit /etc/ssh/sshd_config:

PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes

Then restart the service: systemctl restart ssh.

5. Enable the firewall

ufw allow OpenSSH
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable

Only open what you actually use. Everything else stays closed.

6. Install fail2ban

apt install fail2ban -y

The default configuration already bans IPs that brute-force SSH. For busy servers, raise the ban time in /etc/fail2ban/jail.local.

7. Enable automatic security updates

apt install unattended-upgrades -y
dpkg-reconfigure --priority=low unattended-upgrades

8. Turn on time synchronization

Accurate time matters for logs and TLS. timedatectl set-ntp true is usually all you need.

9. Review listening services

ss -tulpn

Anything listening on 0.0.0.0 that you don't recognise deserves investigation. Databases should listen on 127.0.0.1 unless you have a private network.

10. Set up backups before you need them

A server without backups is a countdown timer. See our guide to the 3-2-1 backup strategy on this blog.

On NetVO infrastructure, enterprise DDoS protection is already filtering traffic before it reaches your server — but host-level hardening is still your responsibility. Ten minutes now saves a very bad weekend later. Questions? Our engineers are available 24/7 through the ticket system.

« Back