check

Is your server at risk?

Ten yes or no questions. Two minutes. A plain-English answer at the end.

It works out your result in your browser. Nothing you choose is sent to me or stored anywhere. If you're not sure of an answer, choose no.

  1. Is the operating system still supported and getting security updates?

    For example, CentOS 7 and Ubuntu 18.04 no longer get free security fixes.

  2. Do you have backups stored somewhere other than the server itself?

    A backup on the same server disappears with it.

  3. Has the server had security updates in the last month?

    Most attacks use holes that already have a fix.

  4. Do you know everyone who can log in, including past staff and developers?

    Old accounts and keys are a common way in.

  5. Are passwords and API keys kept out of your website or app code?

    Keys in code end up in places you can't control.

  6. Does logging in need an SSH key or two-step login, not just a password?

    Passwords alone get guessed by automated attacks every day.

  7. Is the firewall set so only the services you need are open to the internet?

    Every open door is another way in.

  8. Has anyone tested getting data back from a backup in the last six months?

    Untested backups often turn out not to work.

  9. Would someone notice within a day if the server stopped working?

    Without monitoring, problems are found by customers.

  10. Is there a written note of what runs on the server and how to get in?

    If the one person who knows is unavailable, you are stuck.

check-it

Want a proper answer?

A server health check goes through all of this and more on your actual server, with a plain-English report of what to fix first.