Server Hardening

Close SSH, the panel port, and the updates. No suite installed on top.

Key-only SSH, a firewall, Fail2Ban, unattended security updates. We keep a second key in place until you confirm you can still log in.

The list

What actually changes

SSH

Keys, no password, root login off if you have another sudo user. We do not disable your access to prove a point. The test login happens before the old method is closed.

Firewall and Fail2Ban

UFW or nftables, SSH and the web ports public, the panel restricted. Fail2Ban on SSH and on the panel login. Mail ports stay open if mail is on the box.

Updates

Security updates unattended. A PHP major version is not part of hardening. That is a scheduled change, because sites break on it.

Not a pentest

Hardening is the baseline. An audit is the written look.

An audit from €99 lists what is wrong and changes nothing. Hardening is the change, at €55/hour, usually one to three hours on a single VPS. Neither makes the server unhackable. A nulled plugin bypasses both.

Server audit → · Server security →

Price

€55 an hour. The lockout test is included.

Minimum 1 hour. If the only access is a password and one key, we add ours, confirm, then remove password login. You revoke our key when you have logged in yourself.

Pricing →

Password SSH and a panel open to the world?

Tell us the distribution and the panel. We confirm the scope before closing any port.

Request Support → Contact Us