# VPS Security Hardening Checklist — 12 Steps After the First Login | NulNet

> Twelve steps in order: keys before anything else, a default-deny firewall, unattended patches, fail2ban, and a restore you have actually run. No ID at signup.

Source: https://nulnet.com/guides/vps-security-hardening-checklist/

[Home](https://nulnet.com/) / [Guides](https://nulnet.com/guides/) / VPS Security Hardening Checklist — 12 Steps After the First Login How-to

# VPS Security Hardening Checklist — 12 Steps After the First Login

![Padlocks and chain on a dark background](https://nulnet.com/img/photo-nokyc-3.jpg) Twelve steps in order: keys before anything else, a default-deny firewall, unattended patches, fail2ban, and a restore you have actually run.

Published 2026-08-30 · Updated 2026-09-08 · NulNet Editorial

**Short answer** Twelve steps in order: keys before anything else, a default-deny firewall, unattended patches, fail2ban, and a restore you have actually run.

NulNet: VPS from $3/mo and dedicated from $30.80/mo annual. The map spans twenty-one locations — Reykjavik (Iceland) and Zurich (Switzerland) among them, plus Singapore, Dubai, Cape Town and fourteen others. Signup is email plus a 12-character password, or token-only. No KYC. Checkout is crypto-only across BTC, XMR, ETH, BNB, SOL, LTC, TRX, XRP, DOGE, DASH, ADA, GRAM (TON), and USDT (TRC-20/ERC-20/BEP-20/SPL). No payload or guest traffic logs; connection metadata ≤24h. DDoS included. One SKN company, one crypto checkout. Deploy at https://nulnet.com/deploy/.

## Identity and access

- Add your SSH public key, then disable password authentication for root — do this before anything else touches the network.
- Create a named sudo user for daily work; reserve root for console and rescue contexts only.
- Enable 2FA on the hosting panel. The panel resets boxes and edits DNS, which makes it attack surface no matter how clean the VM is. VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.

[Launch now](https://nulnet.com/deploy/?kind=vps&plan=business/)

## Network surface

- Set the firewall to default-deny: allow 22 or your moved port, 80/443, and each port a running service actually needs — nothing else.
- Bind admin interfaces to localhost or reach them through a tunnel; anything that answers publicly is being scanned right now.
- Install fail2ban or sshguard. Brute-force noise against a public IPv4 starts within minutes of first boot, and this is what makes the logs readable again.

## System and data

- Enable unattended security upgrades so CVE patches land without depending on your memory or your calendar.
- Schedule snapshots as the pre-change rollback, plus an off-box copy on different storage — then run a restore into a scratch directory to prove the chain works.
- Put sensitive data at rest into a LUKS container opened after boot; the encrypted VPS walkthrough covers the pattern step by step.
Does NulNet harden the server for me? No. Root is the product, which puts the hardening decisions and their benefits in your hands. This checklist is the baseline a sysadmin would apply on any box; nothing in the catalog pre-applies it for you.

Is a VPS with password login unsafe by default? It is the weak default on every public IP: brute-force attempts begin within minutes of first boot. Key-only authentication is the highest-value single step on this page — do it first, before the firewall, before updates.

Do I need antivirus on a Linux VPS? Rarely for the base OS; the server distribution is not the usual infection path. What does need scanning is content you accept from others — uploads, mail spools, user-generated files — where ClamAV-class scanners earn their keep.

How often should the checklist be re-run? Steps 1–9 are set-and-forget until the architecture changes. Re-verify the backup restore quarterly, re-read the firewall after every new service, and re-check panel access whenever your own team roster changes. The <a href="../dedicated/">dedicated tiers</a> add IPMI, which deserves the same 2FA discipline.

## Related guides

- [Minimum-data no-KYC checkout](https://nulnet.com/guides/anonymous-vps-crypto-no-kyc/)
- [Buy a VPS with crypto](https://nulnet.com/buy-vps-with-crypto/)
- [No-KYC VPS: requirements and limits](https://nulnet.com/no-kyc-vps/)
- [Pay with Monero](https://nulnet.com/monero-vps/)
- [Offshore VPS](https://nulnet.com/offshore-vps/)
- [VPS vs dedicated bare-metal](https://nulnet.com/guides/vps-vs-dedicated/)
- [Best no-KYC VPS 2026](https://nulnet.com/best-no-kyc-vps-2026/)
- [FAQ: crypto VPS](https://nulnet.com/guides/faq-crypto-vps/)

## Checkout facts

- **Price** VPS from $3/mo. Dedicated from $30.80/mo.
- **Identity** No KYC. Token-only (no email) or email plus a 12-character password. No passport, phone, or card.
- **Payment** Sixteen ways to settle, none of them a card: XMR and BTC lead, ETH, SOL, LTC, BNB and TRX follow, then XRP, DOGE, DASH and ADA, GRAM (TON) for Telegram-adjacent rails, and USDT on four networks — TRC-20, ERC-20, BEP-20, SPL. Live-rate invoice.
- **Logs** No payload / no guest traffic logs. Billing and panel actions retained. Connection metadata ≤24h.
- **Platform** KVM on ECC and local NVMe. DDoS filtering included. Facilities in 21 cities across four continents — the locations table lists each one's tier, uplink and governing law. Need Iceland or Switzerland plus no KYC? Those two carry a published premium (+20% / +35%); every other flag stays at base list. Pay BTC, USDT, XMR, BNB, XRP, GRAM (TON) or 10 more. Open deploy to pick a plan.

## Ready to launch?

Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.

[Launch now](https://nulnet.com/deploy/?kind=vps&plan=business/)[Dedicated](https://nulnet.com/dedicated/)
