Quick answer: Cloud2Y secures everything up to your server's network port: physical data centers, the Cisco-based network, host hardware and the optional DDoS filtering. You secure everything inside the server: the operating system, updates, firewall, applications, credentials, data and backups. Unmanaged means the OS is yours.
Overview
The split matters most in incidents: knowing in advance who acts on what saves hours. This shared-responsibility model is standard for unmanaged VPS, VDS and dedicated servers — you get full root/administrator control, and with it full responsibility for what runs under that control.
Before you start
The dividing line is the server boundary:
- Cloud2Y side: data center physical security; power and cooling; network infrastructure and uplinks; virtualization hosts / dedicated hardware health; IP routing; the DDoS protection option; the Client Area and KVM Console.
- Customer side: OS installation choices and updates; SSH and account credentials; firewall rules; application code and CMS plugins; TLS certificates; user data; backups; responding to compromises of your OS.
Step-by-step guide
Turn the model into practice:
- Right after deployment, run the security checklist — that whole list is customer-side.
- Set up off-server backups; Cloud2Y does not back up the contents of your unmanaged server automatically.
- Decide who on your team owns OS patching and reads auth logs.
- Know the escalation paths: hardware/network suspicion or DDoS → ticket to Cloud2Y; hacked application → your admin, with the incident guide.
Common issues
- "The host should have patched my CMS": on unmanaged services nobody but you can log into your OS — plugin and OS patching is yours.
- No backups because "the provider surely has them": it is explicitly your task; a Storage VPS or any offsite target works.
- Asking support to debug application code: out of scope; support covers hardware, network and platform-level issues.
When to contact support
Open a ticket for anything on the Cloud2Y side: suspected hardware faults, network anomalies (how to report), DDoS, or Client Area/KVM access problems.
Frequently asked questions
What security does Cloud2Y provide for my server?
Physical data-center security, the network infrastructure with optional DDoS filtering, healthy host hardware, IP routing, and platform tools like the Client Area and KVM Console.
What am I responsible for on an unmanaged VPS?
Everything inside the OS: updates, firewall, SSH and application credentials, the software you install, your data and its backups, and incident response if the system is compromised.
Does Cloud2Y back up my VPS automatically?
No — on unmanaged services data protection is the customer's task. Set up regular backups to an external target such as a Storage VPS so a failure or compromise never means total loss.
Related articles
- VPS security checklist after deployment
- Cloud2Y DDoS protection overview
- Abuse policy and prohibited activities
- What to do if your server is hacked
Need a hand? Contact Cloud2Y support →
