Debian Server Security Guide: Checklist for Debian 13 and 12

Quick answer: Secure a new Debian 13 (Trixie) or Debian 12 (Bookworm) server in this order: keep it patched, harden SSH, turn on the firewall (with SSH allowed first), add Fail2Ban, then automate security updates. Each step has its own tested guide below. Do them in order, and keep a second SSH session open while you change SSH or firewall settings so a mistake cannot lock you out.

This hub lists the Liberian Geek guides for basic Linux server security on Debian. It is a checklist for a single VPS or dedicated server running a website or small service. It is not a full compliance baseline. Each guide states the Debian versions it applies to and how to verify and undo the change.

The security checklist, in order

Step Guide What it protects against Lockout risk
1. Patch the system Update the kernel on Debian 13 and 12 Known vulnerabilities in the kernel and packages Low. Reboot needed for a new kernel.
2. Harden SSH Harden SSH on Debian 13 and 12 Password guessing and root login over SSH High if you disable passwords before your key works. Test in a second session.
3. Enable the firewall UFW firewall on Debian 13 and 12 Services listening on ports you never meant to expose High if you enable it before allowing SSH.
4. Block repeat offenders Fail2Ban on Debian 13 and 12 Repeated failed logins from the same address Medium. You can ban your own IP; whitelist it.
5. Automate security updates Automatic security updates on Debian 13 and 12 Falling behind on security patches Low. Automatic reboots stay off unless you enable them.

Why this order

Updates come first because every other step relies on current packages. SSH comes before the firewall so you know exactly which port you need to keep open. The firewall comes before Fail2Ban because Fail2Ban adds its own firewall rules and is easier to reason about when the baseline is already in place. Automatic updates go last because they are fire-and-forget once the rest is stable.

How to check each layer is working

Layer Check command What you want to see
SSH configuration sudo sshd -t No output (no syntax errors)
Firewall sudo ufw status verbose Status active, and a rule allowing your SSH port
Fail2Ban sudo fail2ban-client status sshd The sshd jail is listed and running
Automatic updates sudo unattended-upgrade --dry-run -v A list of allowed origins and no errors
Running kernel uname -r The version you expect after the last reboot

Related Debian 13 basics: how APT repositories are configured with deb822 .sources files and how to upgrade Debian 12 to Debian 13. Debian 12’s regular support ended on 12 July 2026, so a server you plan to keep should be on Debian 13.

What this checklist does not cover

It does not replace backups, monitoring, application-level security (for example WordPress or database hardening), or TLS certificates. If you would rather have this done and maintained for you, you can contact us about server setup and hardening.