Guides ยท Sep 27, 2026
How to Secure a New Ubuntu VPS (First 10 Minutes)
A step-by-step checklist to secure a fresh Ubuntu 24.04 VPS: updates, a sudo user, SSH keys, disabling password login, a firewall and automatic security updates.
A brand-new server on the public internet starts receiving automated login attempts within minutes. These steps take about ten minutes and shut down the most common attacks. They assume Ubuntu 24.04, but work the same on 22.04 and 26.04.
1. Log in and update everything
Connect with the root password from your dashboard (or your SSH key):
ssh root@YOUR_SERVER_IP
apt update && apt upgrade -y
2. Create a regular user with sudo
Working as root all the time makes mistakes more dangerous. Create your own user and give it sudo rights:
adduser alex
usermod -aG sudo alex
3. Set up SSH key login
On your own computer (not the server), create a key if you don't have one and copy it to the server:
ssh-keygen -t ed25519
ssh-copy-id alex@YOUR_SERVER_IP
Tip: add your public key under Account โ SSH keys in the dashboard and it will be installed automatically on every new server and reinstall.
Open a new terminal and make sure ssh alex@YOUR_SERVER_IP works before continuing.
4. Turn off password and root login
Once key login works, disable passwords so brute-force attacks become pointless:
sudo nano /etc/ssh/sshd_config.d/00-tidalvps.conf
Change the file to:
PermitRootLogin no
PasswordAuthentication no
sudo systemctl restart ssh
Keep your current session open and test a fresh login in another terminal. If something goes wrong, the web console in your dashboard always works.
5. Enable the firewall
Allow SSH first, then any ports your apps need, then enable UFW:
sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp # only if you run a website
sudo ufw enable
sudo ufw status
6. Install automatic security updates
sudo apt install -y unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades
7. Add Fail2ban (optional but recommended)
Fail2ban blocks IPs that repeatedly fail to log in:
sudo apt install -y fail2ban
sudo systemctl enable --now fail2ban
You're done
Your server now only accepts key-based logins, blocks everything except the ports you opened, and patches itself. Every TidalVPS server also includes always-on DDoS protection and daily backups, so you're covered at the network level too.
Need a server for this?
Every TidalVPS VPS comes with full root access, unmetered traffic, daily backups and DDoS protection.