Securing your VPS in 15 minutes
To be honest, most breaches are lazy configs. As said, this is minimum viable security.
- SSH: key auth only, port 2222 or random high, PermitRootLogin no
- Firewall: ufw or nftables, default deny, open only what you need
- Auto-updates: unattended-upgrades for security repo
- Fail2ban: 3 strikes, 1 hour ban
- AIDE or rkhunter: pick one, schedule weekly
Tested on Debian 12, 2 vCPU, 1GB RAM. Took 14 minutes. Copy-paste friendly.
Dry humor: your password "Correct horse battery staple" is not clever. I have seen it.