Security
Harden your servers and accounts: SSH keys, updates, firewalls, TLS, backups and two-factor authentication.
- How to secure a new Linux server in the first hour A new server is reachable from the internet the moment it boots. These steps close the most common gaps before you install anything else. Beginner 30 min
- SSH hardening: lock down OpenSSH on Ubuntu and Debian With keys in place, a few more SSH settings shrink the attack surface further. Apply them in one drop-in file and verify each change before you log out. Intermediate 20 min
- Block brute-force attacks with Fail2ban or CrowdSec Both tools watch your logs and block addresses that misbehave. Fail2ban is simple and local; CrowdSec adds shared blocklists. Here is how to set up either. Intermediate 20 min
- Automatic security updates on Linux, Windows and macOS servers Most attacks use known flaws for which a fix already exists. Let the server install security updates by itself and plan reboots in a maintenance window. Beginner 15 min
- A backup strategy that works: 3-2-1 for your server Backups only count if you can restore them. Combine the plan's backups with your own encrypted, off-site copies and test a restore regularly. Intermediate 25 min
- How to secure a new Windows Server in the first hour Remote Desktop on the open internet attracts constant password guessing. These steps make a new Windows server a much harder target. Intermediate 25 min
- DDoS protection basics: recognise, mitigate, report Network protection absorbs floods; your server and application handle what remains. Learn the signs, the first steps and what to send us. Intermediate 15 min
- Server hacked? What to do, step by step Stay calm, contain the server, find out how the attacker got in, rebuild from a clean image, restore clean data and rotate every credential. Advanced 30 min