Server Hardening & Security

Bots Are Scanning Your Server Right Now.

Most "security" offerings stop at switching on a firewall and calling it a day. I harden the actual machine — SSH, kernel auditing, app isolation, intrusion detection, and backups you can restore from.

My Main Service

Ubuntu & Linux Server Hardening

This is exactly what I run on my own production server — the one hosting this site and more than a dozen others. Not a checklist I copied off a blog. A setup I maintain, get alerts from, and trust with my own businesses.

Access & Authentication

  • SSH moved off port 22, root login disabled, key-only auth
  • Failed-attempt and session limits, no tunneling or agent forwarding
  • Email alert on every login from an unrecognized IP
  • Least-privilege user accounts and a locked-down sudoers policy

Attack Blocking

  • fail2ban with a repeat-offender jail: 3 strikes bans for a day, 3 bans bans for a month across every port
  • UFW firewall exposing only the ports you actually use
  • Rate limiting on login pages, admin paths, and API endpoints
  • XML-RPC, author enumeration, and PHP execution inside upload folders blocked outright

Isolation Between Apps

  • Every site runs as its own Linux user in its own systemd sandbox
  • NoNewPrivileges, PrivateTmp, ProtectSystem, ProtectHome, ProtectKernelTunables
  • A compromised site cannot read another site’s files or database credentials
  • Shared memory mounted noexec, nosuid, nodev so nothing executes from it

Detection & Alerting

  • Kernel-level auditing on /etc/passwd, /etc/shadow, sudoers, and SSH keys
  • Real-time file-change monitoring across every site directory
  • Nightly malware and rootkit scans (ClamAV, Linux Malware Detect, rkhunter)
  • A daily log digest in your inbox, so you actually read it

Backups & Recovery

  • Encrypted database backups every 2 hours to offsite object storage
  • 30-day offsite retention with restores that have actually been tested
  • Automatic security updates plus a weekly full upgrade, emailed to you
  • Disk-usage alerts before a full volume takes the site down

Self-hosting on a VPS?Hetzner, DigitalOcean, Oracle Cloud, AWS, Linode, or bare metal — I'll take a fresh or neglected Ubuntu box and lock it down end to end, then hand you the documentation so you know exactly what changed and why.

Edge Protection & Cloudflare

Hardening the server stops what reaches it. Cloudflare stops a lot of it from arriving at all. The two work best together.

Cloudflare Setup

DNS, SSL certificates, caching rules, and firewall configuration — set up to protect and accelerate your site, not just proxy it.

Geo-Blocking

Block traffic from countries you do not serve. Smaller attack surface, fewer junk requests in your logs.

Path Protection

Hide admin panels behind Cloudflare Access so attackers cannot even reach the login page, let alone brute-force it.

Zero Trust VPN

Cloudflare Tunnel plus WARP for secure access to internal systems. No open ports, no public IP to attack.

Hidden Admin Paths

Move admin routes off the predictable URLs and put another authentication layer in front of them.

Security Audits

A full review of your application and server. I find the holes before somebody else does, and tell you which ones actually matter.

Windows Servers & Cloud Infrastructure

Linux is where I do most of this work, but I don't leave you stuck if you're on Windows or deep in AWS.

Linux

  • • Ubuntu, Debian, Rocky, Alma
  • • iptables / ufw / firewalld
  • • SSH hardening & key-only auth
  • • systemd service sandboxing
  • • Automatic security updates

Windows Server

  • • Windows Firewall configuration
  • • Account lockout policies
  • • RDP hardening
  • • Port restriction
  • • Update automation & group policy

Cloud & SSL

  • • SSL/TLS certificates & renewal
  • • SMTP with encryption
  • • AWS security groups & VPC
  • • Database access restriction
  • • Monitoring & alerting

AWS since 2015: EC2, RDS, S3, CloudFront, Route 53, and SES. I know where the sharp edges are.

What I Protect You Against

Bot Scanners

Automated tools probing for exposed admin panels and known vulnerabilities. They hit every public server, constantly.

Brute Force Attacks

Password guessing against SSH and login pages. This is the single most common attack on an unhardened box.

SQL Injection

Malicious queries designed to dump or destroy your database.

XSS Attacks

Injected scripts that run in your users’ browsers and steal their sessions.

DDoS Attacks

Traffic floods meant to take you offline, usually at the worst possible moment.

Credential Stuffing

Passwords leaked from other breaches, replayed against your login until one works.

Security Packages

Most Requested
Server Hardening
$400 - $1,200
  • • Full Ubuntu / Linux lockdown
  • • SSH, firewall, fail2ban
  • • App isolation & sandboxing
  • • Intrusion detection & alerts
  • • Automated offsite backups
  • • Written documentation
Get Started
Cloudflare Setup
$300 - $500
  • • DNS configuration
  • • SSL/TLS setup
  • • Firewall rules
  • • Caching optimization
Get Started
Server + Edge
$500 - $1,500
  • • Everything in Server Hardening
  • • Cloudflare configuration
  • • Geo-blocking
  • • Hidden admin paths
  • • Rate limiting & bot protection
Get Started
Zero Trust
$1,000 - $2,500
  • • Everything in Server + Edge
  • • Cloudflare Tunnel setup
  • • WARP client configuration
  • • Access policies
  • • Internal app protection
Get Started

Already have a server that's been running untouched for years? That's the most common thing I get handed. Ask for a free assessment.