Quick answer: On an unmanaged VPS, VDS or dedicated server the customer is responsible for OS-level security: passwords and keys, updates, firewall, exposed services and application hygiene. Cloud2Y secures the infrastructure underneath and offers DDoS protection as an order option, but cannot patch or configure your server for you.

Overview

Full root access means full control — and full responsibility. Most real-world compromises come from a handful of preventable causes: weak or reused passwords, unpatched software, abandoned plugins and unnecessary services listening on public ports. Treating security as a first-day setup task (not an afterthought) prevents nearly all of them.

Before you start

  • Plan security into deployment day — the window between first boot and first hardening is when default credentials are most vulnerable.
  • Know your attack surface: every open port and every installed web application is part of it.
  • Remember that consequences are yours too: a compromised server can be suspended under the AUP until fixed.

Step-by-step guide

The customer-side security baseline:

  1. Change default credentials immediately; prefer SSH keys and disable password login.
  2. Keep the OS and applications updated on a schedule, not "when remembered".
  3. Run a firewall that allows only the ports you actually serve.
  4. Install an intrusion deterrent (Fail2ban or equivalent) for exposed services.
  5. Monitor logs and resource anomalies — early detection turns incidents into non-events.
  6. Keep offsite backups so that worst-case recovery is a restore, not a loss.

Common issues

  • "The host should have blocked it": traffic to services you expose is your perimeter — the platform cannot know which logins are legitimate.
  • Set-and-forget servers: unmaintained instances are the top abuse source; schedule updates or decommission unused machines.
  • Panel ≠ security: a control panel simplifies management but still needs its own updates and 2FA.

When to contact support

Contact support if you suspect platform-level issues, need rescue/KVM access to recover a locked-down server, received an abuse notice you need context on, or want DDoS protection options for your service.

Frequently asked questions

What security tasks am I responsible for on my VPS?

Everything inside the OS: credentials and SSH keys, timely updates, firewall rules, exposed services, monitoring and offsite backups. The platform underneath is secured by Cloud2Y.

Can my service be suspended because it was hacked?

Yes, if the compromise causes abuse such as spam or attacks and stays unfixed. Cleaning the server quickly and replying in the abuse ticket normally keeps the service running.

Does Cloud2Y offer anything to help with attacks?

DDoS protection is available as an order option and the KVM Console gives you out-of-band access for recovery. OS-level hardening remains your side of the split.

Related articles

Need a hand? Contact Cloud2Y support →

Was this answer helpful? 0 Users Found This Useful (0 Votes)