Protection
- A firewall that is closed by default: only the ports your services need are open.
- Automatic bans for repeated failed logins and for scanning, before an attacker gets lucky.
- Web application firewall rules that drop injection and file-probing requests before your code sees them.
- Key-only SSH, no root logins and a separate user for each site.
- Strong TLS settings, with certificates issued and renewed for you.
- On our servers, DDoS and DNS-flood filtering at the data-centre edge sits in front of all of it.
