A server is a computer that stays on and serves your website. Root is the all-powerful admin user on it. VPS and dedicated server owners have root. Shared hosting users can follow the account-level tips.
The 15 practices
- Use strong passwords. Make them long, with letters, numbers and symbols. Never reuse them.
- Keep software updated. Updates fix known holes. This covers the OS, control panel and apps.
- Use a firewall. A firewall is a guard that blocks unwanted traffic. Allow only the ports you need.
- Use SSH keys. SSH is how you control a server by commands. A key is a long secret file that is safer than a password.
- Turn off direct root login. Use a normal user, then gain admin power when needed.
- Change the default SSH port. This reduces random attacks.
- Limit login attempts. Tools such as Fail2ban block an address after many wrong tries.
- Remove unused software. Less software means fewer weak points.
- Close unused ports. A port is a numbered door on the server. Close what you do not use.
- Use SSL. SSL encrypts the data between visitors and your site.
- Take regular backups. Keep a copy away from the server. Test that you can restore it.
- Scan for malware. Run scans on a schedule.
- Check logs. Logs are diaries of what happened. Odd entries can show an attack.
- Give users only the access they need. Remove accounts that are no longer in use.
- Turn on two-factor login. It asks for a code from your phone as well as a password.
Steps to start today
- Change your main passwords.
- Install pending updates.
- Check your firewall rules.
- Set up a backup that runs by itself.
Warning: Some changes, like the SSH port or the firewall, can lock you out. Keep one login open and test a second before you close it. Take a backup first.
Ask Hostvento support which security tools are on your plan. You can open a ticket any time.
Quick recap
- Strong passwords and updates come first.
- Use a firewall and block repeated bad logins.
- Prefer SSH keys, and avoid direct root login.
- Back up often and test restores.
- Watch your logs and remove unused access.