Services / Security & hardening
Security & hardening
Smaller teams are targeted precisely because attackers assume nobody's watching: default SSH ports, password auth, and unpatched packages are common, not rare. We close the gaps that actually get exploited: access control, patching, and the basic hygiene most breaches trace back to.
What's included
- Firewall configuration (ufw, iptables or cloud security groups)
- SSH key-only access, password authentication disabled
- fail2ban and intrusion detection
- Patch cadence and vulnerability tracking
- Periodic security audits with a written report
Standard remote and on-site support in Calgary. Fixed-scope project quotes available on request.
Frequently asked questions
Yes, often more so, since attackers assume smaller teams aren't watching closely. Default SSH ports, password auth, and unpatched packages get scanned for constantly, regardless of company size.
SSH: switching to key-only access with password authentication disabled, plus fail2ban. It's the single most commonly exploited gap we see.
Yes, a written report covering what was found and what was changed, not just a verbal summary.
FROM THE BLOG
Related reading
Most server compromises aren't sophisticated. They exploit the same handful of unhardened defaults. Here's the checklist that closes them.
Turning off password auth is where most SSH hardening guides stop. Here's what actually closes the gap.
OTHER SERVICES
Often paired with this
Provisioning, patching, hardening and day-to-day care for Debian, Ubuntu, RHEL and CentOS systems.
KVM and Proxmox VE virtual machines for isolating workloads and getting more out of the hardware you already own.
Nginx/Apache stacks, SSL, deploy pipelines and staging environments configured and kept running.