{"id":23072,"date":"2026-05-04T08:19:30","date_gmt":"2026-05-04T08:19:30","guid":{"rendered":"https:\/\/atalnetworks.com\/?p=23072"},"modified":"2026-05-10T13:39:47","modified_gmt":"2026-05-10T13:39:47","slug":"network-security-for-dedicated-server","status":"publish","type":"post","link":"https:\/\/atalnetworks.com\/es\/network-security-for-dedicated-server\/","title":{"rendered":"Network Security for Dedicated Server Clients: The 2026 Reality"},"content":{"rendered":"<p>Q1 2026 saw 1,138 ransomware attacks across the Americas with average payments hitting $4.2 million\u2014up 38% from 2025. AI-enhanced ransomware achieves 73% success rates, with attacker dwell time dropping from 9 days to 47 hours.<\/p>\n<p>For dedicated server clients, this is your threat environment. Unlike managed cloud services, you own complete security responsibility\u2014from OS hardening to incident response. More control means better performance, but every security gap is yours to close.<\/p>\n<p>The cost of failure: GDPR violations reach \u20ac20 million or 4% global revenue. HIPAA breaches average $7.42 million. PCI DSS non-compliance brings $5,000-$100,000 monthly fines. Then customer trust evaporates.<\/p>\n<p>This guide covers network security for dedicated servers\u2014not generic tips, but a framework addressing how attacks unfold and how businesses respond.<\/p>\n<h2><b>Table of Contents<\/b><\/h2>\n<ul>\n<li><a href=\"#mission-critical\">Why Security Became Mission-Critical in 2026<\/a><\/li>\n<li><a href=\"#attack-patterns\">Three Attack Patterns Targeting Dedicated Servers<\/a><\/li>\n<li><a href=\"#foundation-layer\">Foundation Layer: Non-Negotiable Controls<\/a><\/li>\n<li><a href=\"#ddos-protection\">DDoS Protection: Why Firewalls Fail<\/a><\/li>\n<li><a href=\"#ransomware-defense\">Ransomware Defense: Surviving Breaches<\/a><\/li>\n<li><a href=\"#monitoring\">Monitoring: You Can&#8217;t Protect What You Can&#8217;t See<\/a><\/li>\n<li><a href=\"#compliance\">Compliance as Security Framework<\/a><\/li>\n<li><a href=\"#incident-response\">Incident Response: When Attackers Get In<\/a><\/li>\n<li><a href=\"#atal-foundation\">Atal Networks Security Foundation<\/a><\/li>\n<li><a href=\"#faq\">PREGUNTAS FRECUENTES<\/a><\/li>\n<li><a href=\"#building-security\">Building Security That Survives<\/a><\/li>\n<li><a href=\"#take-action\">Take Action Today<\/a><\/li>\n<li><a href=\"#deploy-infrastructure\">Deploy Secure Infrastructure<\/a><\/li>\n<\/ul>\n<h2><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-full wp-image-23081\" src=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Why-Security-Became-Mission-Critical-in-2026.webp\" alt=\"Why Security Became Mission-Critical in 2026\" width=\"1376\" height=\"768\" srcset=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Why-Security-Became-Mission-Critical-in-2026.webp 1376w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Why-Security-Became-Mission-Critical-in-2026-300x167.webp 300w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Why-Security-Became-Mission-Critical-in-2026-1024x572.webp 1024w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Why-Security-Became-Mission-Critical-in-2026-768x429.webp 768w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Why-Security-Became-Mission-Critical-in-2026-18x10.webp 18w\" sizes=\"(max-width: 1376px) 100vw, 1376px\" \/><\/h2>\n<h2 id=\"mission-critical\">Why Security Became Mission-Critical in 2026<\/h2>\n<p>Three forces converged:<\/p>\n<p><strong>Ransomware professionalized.<\/strong> <a href=\"https:\/\/www.cisa.gov\/stopransomware\" target=\"_blank\" rel=\"noopener\">Ransomware-as-a-Service<\/a> lets low-skilled affiliates launch enterprise attacks. Volume up 47%, though payments declined as defenses improved.<\/p>\n<p><strong>AI transformed attacks.<\/strong> Autonomous reconnaissance at 36,000 probes\/second. Polymorphic malware rewrites itself. Attack lifecycles compressed 80%. <a href=\"https:\/\/www.cisa.gov\/\" target=\"_blank\" rel=\"noopener\">CISA<\/a> reports defenders have hours, not days.<\/p>\n<p><strong>Identity became the entry point.<\/strong> 1.8 billion credentials stolen H1 2025. Attackers log in legitimately, bypassing perimeter defenses. No malware signature. No vulnerability. Just valid access.<\/p>\n<p>The paradox: You chose dedicated hosting for control. That control means responsibility. Backups fail when attackers leak data. Firewalls can&#8217;t stop insiders. Patches don&#8217;t help against zero-days. Success requires defense in depth and assume breach mentality.<\/p>\n<h2><img decoding=\"async\" class=\"alignnone size-full wp-image-23082\" src=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Three-Attack-Patterns-Targeting-Dedicated-Servers.webp\" alt=\"Three Attack Patterns Targeting Dedicated Servers\" width=\"1500\" height=\"837\" srcset=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Three-Attack-Patterns-Targeting-Dedicated-Servers.webp 1500w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Three-Attack-Patterns-Targeting-Dedicated-Servers-300x167.webp 300w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Three-Attack-Patterns-Targeting-Dedicated-Servers-1024x571.webp 1024w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Three-Attack-Patterns-Targeting-Dedicated-Servers-768x429.webp 768w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Three-Attack-Patterns-Targeting-Dedicated-Servers-18x10.webp 18w\" sizes=\"(max-width: 1500px) 100vw, 1500px\" \/><\/h2>\n<h2 id=\"attack-patterns\">Three Attack Patterns Targeting Dedicated Servers<\/h2>\n<h3>Triple Extortion Ransomware<\/h3>\n<p>Modern ransomware goes beyond encryption. Attackers infiltrate networks through compromised credentials or phishing, spend weeks identifying critical systems, exfiltrate sensitive data, then encrypt.<\/p>\n<p>The extortion: Pay for decryption keys. When you restore from backups, they threaten to publish stolen data. Still refuse? They launch DDoS attacks during recovery. Some groups contact your customers directly. Black Cat even filed SEC complaints against victims for delayed breach disclosure.<\/p>\n<p>According to <a href=\"https:\/\/www.recordedfuture.com\/\" target=\"_blank\" rel=\"noopener\">Recorded Future<\/a>, attacks rose to 7,200 in 2025 from 4,900 in 2024\u201447% increase. Average payments declined as organizations implemented better recovery. This drives groups toward more aggressive tactics.<\/p>\n<p><strong>Why backups alone fail:<\/strong> You can restore encrypted files. You cannot un-steal data. Data exposure becomes permanent regardless of recovery capabilities.<\/p>\n<h3>Identity-Led Compromise<\/h3>\n<p>Attackers obtain credentials through phishing, credential stuffing, or buying access from brokers. With valid credentials, they authenticate through VPN or SSH like legitimate users. Security tools see normal login behavior because it is normal\u2014credentials are valid.<\/p>\n<p>Inside, attackers use native admin tools. On Linux: SSH, rsync, bash scripts. These tools exist legitimately, making malicious use nearly invisible. Traditional antivirus can&#8217;t detect it\u2014no malicious files. Only behavioral analysis catches compromised accounts executing unusual commands.<\/p>\n<p>The credential theft economy matured. Infostealers harvested 1.8 billion credentials H1 2025. Brokers sell to ransomware affiliates. Time between theft and malicious use: hours.<\/p>\n<p><strong>Defense shift required:<\/strong> MFA becomes non-negotiable. Privileged access management grants time-limited elevation instead of permanent sudo. Behavioral monitoring watches for unusual access patterns\u2014legitimate credentials at unusual times, locations, or accessing unusual data.<\/p>\n<h3>AI-Powered Reconnaissance<\/h3>\n<p>AI reconnaissance scans thousands of targets simultaneously, identifying vulnerable services and misconfigurations in minutes. Polymorphic malware rewrites itself continuously\u2014same malicious function, different appearance to evade signature detection. Some variants detect analysis sandboxes, staying dormant during testing.<\/p>\n<p>Autonomous exploitation chains represent the biggest concern. AI agents identify vulnerabilities, chain exploits for privilege escalation, adapt to defenses\u2014all without human intervention. Researchers predict mid-2026 will see major breaches where AI conducts entire attack lifecycles autonomously.<\/p>\n<p><strong>Impact:<\/strong> Attack windows compressed. Manual security processes can automation becomes mandatory for patching, detection, and response.<\/p>\n<h2><img decoding=\"async\" class=\"alignnone size-full wp-image-23083\" src=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/foundation-layer-scaled.webp\" alt=\"foundation layer\" width=\"2560\" height=\"1429\" srcset=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/foundation-layer-scaled.webp 2560w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/foundation-layer-300x167.webp 300w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/foundation-layer-1024x572.webp 1024w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/foundation-layer-768x429.webp 768w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/foundation-layer-1536x857.webp 1536w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/foundation-layer-2048x1143.webp 2048w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/foundation-layer-18x10.webp 18w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/h2>\n<h2 id=\"foundation-layer\">Foundation Layer: Non-Negotiable Controls<\/h2>\n<h3>Patch Management That Works<\/h3>\n<p>Unpatched vulnerabilities = #1 exploit vector. Automated bots scan continuously, exploiting within hours of disclosure. Manual patching can&#8217;t keep pace.<\/p>\n<p>Enable automated security updates: <code>unattended-upgrades<\/code> (Ubuntu\/Debian) or <code>dnf-automatic<\/code> (RHEL\/CentOS). Configure for automatic security patches; reserve major upgrades for manual testing. Kernel live patching (Ubuntu Livepatch, Red Hat kpatch) applies critical updates without reboots.<\/p>\n<p>Beyond OS: Keep web servers, databases, runtimes current. Test updates in staging before production. Verify with weekly vulnerability scans using <a href=\"https:\/\/www.openvas.org\/\" target=\"_blank\" rel=\"noopener\">OpenVAS<\/a>, Nessus, or Qualys.<\/p>\n<h3>SSH Hardening: Your Primary Access Vector<\/h3>\n<p>SSH receives constant attacks. Automated bots continuously probe port 22 attempting brute-force password guessing, credential stuffing with breached password lists, and exploitation of SSH service vulnerabilities.<\/p>\n<p><strong>Why SSH hardening matters:<\/strong> Every failed authentication attempt in your logs represents an actual attack. Unhardened SSH servers receive thousands of attack attempts daily. Proper hardening eliminates entire attack categories.<\/p>\n<p><strong>Key-based authentication only.<\/strong> Generate strong SSH key pairs using either RSA 4096-bit keys or modern Ed25519 keys which provide equivalent security with better performance. Distribute public keys to your server&#8217;s <code>~\/.ssh\/authorized_keys<\/code> file, configure SSH to accept only key-based authentication via <code>PubkeyAuthentication yes<\/code>, then disable password authentication completely with <code>PasswordAuthentication no<\/code>. This single change eliminates brute force attacks\u2014password guessing cannot succeed when passwords are not accepted.<\/p>\n<p>Protect private keys with passphrase encryption. An unencrypted private key discovered on a compromised laptop grants immediate server access. Implement key rotation policies for sensitive environments, replacing SSH keys on defined schedules to limit exposure windows if keys become compromised.<\/p>\n<p><strong>Change default port from 22.<\/strong> This doesn&#8217;t provide security through obscurity\u2014determined attackers will find your SSH port regardless. It does dramatically reduce log noise from automated scanning scripts that exclusively target port 22. Your logs become far easier to analyze when they contain actual security events rather than thousands of failed bot attempts daily. Choose a random port above 1024.<\/p>\n<p><strong>Disable root login completely.<\/strong> Set <code>PermitRootLogin no<\/code> in SSH configuration. Administrative users should connect with personal accounts then elevate privileges through sudo. This creates audit trails that identify which specific administrator performed which actions. When something goes wrong, you know who to ask instead of seeing only &#8220;root&#8221; in logs.<\/p>\n<p><strong>Add multi-factor authentication (MFA).<\/strong> Google Authenticator PAM modules integrate with SSH, requiring both key-based authentication and time-based one-time password (TOTP) codes for successful connections. Configure this by installing <code>libpam-google-authenticator<\/code> and adding authentication requirements to PAM configuration. This protects against scenarios where private SSH keys are compromised through laptop theft, malware, or social engineering.<\/p>\n<p><strong>Deploy Fail2Ban for automated response.<\/strong> <a href=\"https:\/\/www.fail2ban.org\/\" target=\"_blank\" rel=\"noopener\">Fail2Ban<\/a> monitors log files for repeated failed authentication attempts, temporarily or permanently banning offending IP addresses through firewall rules. Configure it to ban IPs after three failed SSH attempts within ten minutes. Legitimate users rarely trigger this threshold accidentally, while automated attacks get blocked immediately, reducing server load and log noise.<code><\/code><\/p>\n<p>After modifying SSH configuration, always test new settings before disconnecting your current session. Maintain one active connection while testing new connection attempts from another terminal to avoid locking yourself out. Verify you can connect with keys, MFA works correctly, and password authentication is truly disabled by attempting password-based connection (which should fail).<\/p>\n<h3>Firewall Architecture: Defense in Depth<\/h3>\n<p>Properly configured firewalls control which network traffic reaches your server and which connections your server initiates. The default-deny philosophy guides effective configuration: block everything by default, then explicitly allow only necessary services.<\/p>\n<p><strong>Host-based firewalls<\/strong> run directly on servers, providing the last line of network defense. UFW (Uncomplicated Firewall) on Ubuntu systems and firewalld on RHEL-family distributions provide accessible interfaces to underlying iptables\/nftables packet filtering frameworks.<\/p>\n<p>Essential ports for typical web servers include HTTP (80), HTTPS (443), and your custom SSH port. Every additional open port expands attack surface. Database servers commonly use ports 3306 (MySQL), 5432 (PostgreSQL), or 27017 (MongoDB), but these should never be directly accessible from the internet. Restrict database ports to localhost or specific internal IP addresses using firewall rules that permit access only from application servers that legitimately need database connectivity.<\/p>\n<p><strong>Egress filtering<\/strong> controls outbound traffic alongside inbound restrictions. This often-overlooked defensive layer protects against data exfiltration. Compromised servers frequently attempt outbound connections to command-and-control infrastructure for instructions or data exfiltration endpoints for stolen information. Egress rules limit which external services your server can contact\u2014for example, allowing updates from official repositories while blocking connections to unknown destinations. This reduces attackers&#8217; ability to leverage compromised systems even after gaining initial access.<code><\/code><\/p>\n<p><strong>Web Application Firewall (WAF)<\/strong> provides Layer 7 protection against application-specific attacks that network firewalls cannot recognize. Unlike network firewalls that analyze packet headers, WAFs understand HTTP\/HTTPS protocols and identify attacks like SQL injection attempts, cross-site scripting (XSS), command injection, and other vulnerabilities from the <a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_blank\" rel=\"noopener\">OWASP Top 10<\/a>. Modern WAFs include rate limiting to prevent abuse, geographic IP blocking to restrict access from high-risk regions, and machine learning capabilities that improve threat detection over time by analyzing attack patterns.<\/p>\n<p><strong>Network segmentation<\/strong> divides infrastructure into isolated zones based on security requirements and trust levels. Database servers operate in protected network segments accessible only from application servers through specific ports\u2014typically on private network interfaces not exposed to the internet. Public-facing web servers sit in demilitarized zones (DMZ)\u2014network segments positioned between external networks and internal infrastructure. Compromised DMZ systems cannot easily pivot to attack internal resources because network segmentation blocks lateral movement by default.<\/p>\n<p><a href=\"https:\/\/www.pcisecuritystandards.org\/\" target=\"_blank\" rel=\"noopener\">PCI DSS compliance requirements<\/a> explicitly mandate network segmentation for environments processing payment card data. Systems storing, processing, or transmitting cardholder data must be isolated from general corporate networks. This compliance requirement simultaneously improves overall security posture by containing potential breaches and limiting the scope of security controls required to meet compliance standards.<\/p>\n<h3>Access Control<\/h3>\n<p><strong>Least privilege principle:<\/strong><\/p>\n<ul>\n<li>Individual accounts (never shared root)<\/li>\n<li>Sudo without NOPASSWD (except specific scripts)<\/li>\n<li>Service accounts for apps (web server \u2260 root)<\/li>\n<li>MFA on administrative interfaces<\/li>\n<\/ul>\n<p>Role-based access control (RBAC) assigns permissions by job function. Define roles with specific permissions. Personnel changes = role reassignment, not permission reconfiguration.<\/p>\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-23084\" src=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041557.jpeg\" alt=\"Dedicated_server_security_visual\u2026\" width=\"1376\" height=\"768\" srcset=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041557.jpeg 1376w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041557-300x167.jpeg 300w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041557-1024x572.jpeg 1024w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041557-768x429.jpeg 768w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041557-18x10.jpeg 18w\" sizes=\"(max-width: 1376px) 100vw, 1376px\" \/><\/h2>\n<h2 id=\"ddos-protection\">DDoS Protection: Why Firewalls Fail<\/h2>\n<p>Volumetric DDoS floods network connections. If attackers send 100 Gbps at your 10 Gbps pipe, 90 Gbps never reaches your firewall\u2014it saturates uplink first, making your server unreachable regardless of CPU power or firewall rules.<\/p>\n<p><strong>The physics problem:<\/strong> Bandwidth exhaustion happens upstream from defensive controls. Host-based firewalls can&#8217;t protect against saturation occurring before traffic reaches them.<\/p>\n<p><strong>Effective protection:<\/strong> Upstream mitigation through scrubbing centers. Traffic redirects through cleaning facilities via BGP routing, gets filtered, then forwarded to your server. You receive only legitimate traffic during attacks.<\/p>\n<p><strong>Atal Networks approach:<\/strong> 40 Gbit\/s DDoS protection included with every <a href=\"https:\/\/atalnetworks.com\/es\/dedicated-servers\/\">Servidor dedicado<\/a>. Always-on network-level filtering prevents bandwidth saturation. No manual activation delays. Upgradeable for higher-risk workloads.<\/p>\n<p><strong>Application-layer defense:<\/strong> Rate limiting, CAPTCHA challenges, CDN integration supplement upstream protection against sophisticated Layer 7 attacks.<\/p>\n<h2 id=\"ransomware-defense\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-23086\" src=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041601.webp\" alt=\"\" width=\"1376\" height=\"768\" srcset=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041601.webp 1376w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041601-300x167.webp 300w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041601-1024x572.webp 1024w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041601-768x429.webp 768w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041601-18x10.webp 18w\" sizes=\"(max-width: 1376px) 100vw, 1376px\" \/><br \/>\nRansomware Defense: Surviving Breaches<\/h2>\n<p>Assume breach. Determined attackers will eventually get in. Can you minimize impact and recover quickly?<\/p>\n<h3>Immutable Backups<\/h3>\n<p><strong>3-2-1 rule:<\/strong> 3 copies, 2 media types, 1 offsite. Guards against hardware failure and site disasters.<\/p>\n<p><strong>Immutability matters:<\/strong> Modern ransomware targets backups. Write-once-read-many (WORM) storage prevents modification even by admins. Attackers can&#8217;t encrypt backups they can&#8217;t modify.<\/p>\n<p><strong>Air-gapped storage:<\/strong> Physical network separation. Backups on disconnected media can&#8217;t be reached even with complete network access.<\/p>\n<p><strong>Test weekly:<\/strong> Restore to staging, verify integrity, document procedures. Backup strategy = last successful test.<\/p>\n<p><strong>RTO\/RPO:<\/strong> Recovery Time Objective = how fast you restore. Recovery Point Objective = maximum data loss tolerance. These metrics drive backup frequency and architecture.<\/p>\n<p>Real scenario: Healthcare provider hit with ransomware. Database unaffected (network segmentation). Restored web servers from immutable backups in 4 hours. No data exposure, no HIPAA breach. Cost: $12K labor + downtime. Same attack without preparation averages $2.3M per <a href=\"https:\/\/www.ibm.com\/security\/data-breach\" target=\"_blank\" rel=\"noopener\">IBM&#8217;s breach report<\/a>.<\/p>\n<h3>Endpoint Detection &amp; Response (EDR)<\/h3>\n<p>Traditional antivirus = signature-based. Fails against living-off-the-land attacks (no malicious files) and polymorphic malware.<\/p>\n<p><strong>EDR analyzes behavior:<\/strong><\/p>\n<ul>\n<li>Credential theft detection<\/li>\n<li>Lateral movement tracking<\/li>\n<li>Automated containment<\/li>\n<li>Forensic evidence collection<\/li>\n<\/ul>\n<p>Business case: $4.2M average ransom vs. $50-$150\/endpoint annually for EDR. Organizations with EDR detect + contain ransomware before encryption far more frequently.<\/p>\n<h3>Network Segmentation<\/h3>\n<p>Divide infrastructure into isolated zones. Communication between zones requires explicit authorization.<\/p>\n<p>Web servers in DMZ can&#8217;t directly access database servers. Databases accept connections only from authorized app servers on specific ports. Ransomware infecting web servers can&#8217;t spread to databases, backups, or admin systems.<\/p>\n<p><strong>Implementation:<\/strong> VLANs, private networks, micro-segmentation. Limit blast radius even when attackers penetrate perimeter.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-23087\" src=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041605.webp\" alt=\"Dedicated_server_security_visual\u2026_202605041605\" width=\"1376\" height=\"768\" srcset=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041605.webp 1376w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041605-300x167.webp 300w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041605-1024x572.webp 1024w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041605-768x429.webp 768w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041605-18x10.webp 18w\" sizes=\"(max-width: 1376px) 100vw, 1376px\" \/><\/p>\n<h2 id=\"monitoring\">Monitoring: You Can&#8217;t Protect What You Can&#8217;t See<\/h2>\n<p>Security monitoring provides visibility needed to detect attacks early\u2014ideally before they escalate to full compromises. The shift from reactive to proactive security depends entirely on visibility.<\/p>\n<h3>Centralized Logging (SIEM)<\/h3>\n<p>Security Information and Event Management (SIEM) systems aggregate logs from all infrastructure components into unified platforms where correlation and analysis occur. The fundamental problem SIEM solves: individual system logs reveal local events, but attacks typically manifest across multiple systems simultaneously.<\/p>\n<p>An attacker might probe your firewall from one IP address while attempting SSH authentication from another IP, then accessing a web application from a third. Each system logs these events independently. Only centralized log aggregation reveals these seemingly unrelated activities as components of a coordinated campaign originating from the same threat actor.<\/p>\n<p><strong>SIEM platforms use correlation rules<\/strong> to detect complex attack indicators. Example correlation: Failed SSH authentication attempts from a specific IP address followed by successful authentication from the same source within 24 hours triggers high-priority alerts. This pattern suggests potential credential compromise through brute force or credential stuffing\u2014something individual log entries cannot reveal.<\/p>\n<p><strong>Key metrics requiring continuous monitoring:<\/strong><\/p>\n<p><strong>Failed authentication attempts<\/strong> indicate potential brute-force attacks. Patterns matter more than individual events. Repeated failures from single IP addresses suggest automated attack tools systematically testing credentials. Failed attempts using valid usernames but incorrect passwords indicate attackers who partially compromised your user database or obtained username lists through reconnaissance.<\/p>\n<p><strong>Unusual outbound connections<\/strong> often reveal compromised systems. Servers typically communicate with predictable destinations\u2014operating system update repositories, monitoring systems, database replication targets, content delivery networks. Unexpected outbound connections to unfamiliar IP addresses, especially on unusual ports or to countries where you don&#8217;t operate, suggest malware command-and-control communication or data exfiltration attempts. DNS queries for suspicious domains can also indicate malware attempting to resolve C2 infrastructure.<\/p>\n<p><strong>Privilege escalation events<\/strong> demand immediate investigation. Every sudo command execution, every elevation to root privileges, every administrative action generates log entries. Unexpected privilege escalation\u2014especially from service accounts that shouldn&#8217;t require elevated access or during off-hours when no administrators should be working\u2014requires urgent response. This often represents the moment attackers transition from initial compromise to system takeover.<\/p>\n<p><strong>File integrity changes<\/strong> to critical system files indicate potential tampering. Attackers frequently modify system binaries to hide their presence, alter configuration files to maintain persistence, or install kernel modules for rootkit functionality. File integrity monitoring using tools like AIDE (Advanced Intrusion Detection Environment) or Tripwire detects these unauthorized changes in real-time by comparing current file states against known-good baselines.<\/p>\n<p><strong>Resource anomalies<\/strong> like CPU or RAM spikes without corresponding legitimate workload increases often indicate cryptocurrency mining malware (which consumes substantial CPU resources), participation in DDoS botnets (which can spike network utilization), or other malicious resource consumption. Establish baseline resource usage patterns, then alert on significant deviations.<\/p>\n<p>Long-term log retention serves both compliance requirements and forensic analysis needs. Regulations like <a href=\"https:\/\/www.pcisecuritystandards.org\/\" target=\"_blank\" rel=\"noopener\">PCI DSS<\/a> mandate retaining logs for at least one year, with three months immediately accessible for analysis. Beyond compliance obligations, historical logs enable forensic investigations to determine attack timelines, identify initial compromise vectors when incidents are discovered months after they occurred, and understand attacker behavior patterns that inform defensive improvements.<\/p>\n<h3>Intrusion Detection<\/h3>\n<p><strong>Network IDS (NIDS):<\/strong> Monitors traffic for port scans, exploits, malware signatures. <strong>Host IDS (HIDS):<\/strong> Watches file mods, process behavior, config changes. <strong>Signature-based:<\/strong> Catches known attacks. <strong>Anomaly-based:<\/strong> Identifies deviations from normal\u2014catches zero-days but generates more false positives.<\/p>\n<h3>Vulnerability Management<\/h3>\n<p><strong>Weekly scans:<\/strong> OpenVAS, Nessus, Qualys identify missing patches, misconfigurations. <strong>Quarterly penetration testing:<\/strong> Required by <a href=\"https:\/\/www.pcisecuritystandards.org\/\" target=\"_blank\" rel=\"noopener\">PCI DSS<\/a>, smart for everyone. Simulates real attacks to find weaknesses scans miss. <strong>Patch prioritization:<\/strong> Fix remotely exploitable vulnerabilities in internet-facing services first.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-23088\" src=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041612.jpeg\" alt=\"\" width=\"1376\" height=\"768\" srcset=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041612.jpeg 1376w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041612-300x167.jpeg 300w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041612-1024x572.jpeg 1024w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041612-768x429.jpeg 768w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041612-18x10.jpeg 18w\" sizes=\"(max-width: 1376px) 100vw, 1376px\" \/><\/p>\n<h2 id=\"compliance\">Compliance as Security Framework<\/h2>\n<p>Regulations encode proven practices into auditable requirements.<\/p>\n<h3>GDPR (EU Personal Data)<\/h3>\n<p><strong>Penalty:<\/strong> \u20ac20M or 4% global revenue, whichever higher. <a href=\"https:\/\/edpb.europa.eu\/\" target=\"_blank\" rel=\"noopener\">EU enforcement<\/a> increasingly aggressive.<\/p>\n<p><strong>Requirements:<\/strong><\/p>\n<ul>\n<li>Encryption at rest + in transit (full disk encryption, TLS 1.3)<\/li>\n<li>Access controls with audit trails (RBAC, MFA)<\/li>\n<li>Breach notification within 72 hours<\/li>\n<\/ul>\n<p><strong>Security benefit:<\/strong> Forced encryption, access control, monitoring protect against real threats. Compliance drives better security.<\/p>\n<h3>HIPAA (US Healthcare)<\/h3>\n<p><strong>Penalty:<\/strong> Up to $1.5M annually per violation category. <a href=\"https:\/\/www.hhs.gov\/hipaa\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">HHS<\/a> actively enforces.<\/p>\n<p><strong>Requirements:<\/strong><\/p>\n<ul>\n<li>ePHI encryption (patient data at rest + transit)<\/li>\n<li>MFA for admin access<\/li>\n<li>Business Associate Agreements (BAAs)<\/li>\n<li>Annual risk assessments<\/li>\n<\/ul>\n<p><strong>Implementation:<\/strong> Encrypted backups, VPN-only admin access, session timeouts. Check Atal Networks HIPAA compliance.<\/p>\n<h3>PCI DSS (Payment Cards)<\/h3>\n<p><strong>Penalty:<\/strong> $5K-$100K\/month from banks, potential relationship termination. <a href=\"https:\/\/www.pcisecuritystandards.org\/\" target=\"_blank\" rel=\"noopener\">PCI SSC<\/a> enforces.<\/p>\n<p><strong>12 requirements:<\/strong> Firewalls, encryption, access control, monitoring, testing, policies.<\/p>\n<p><strong>Compliance levels:<\/strong> Based on transaction volume. 6M+ annually = quarterly scans + annual audit. Lower volumes = Self-Assessment Questionnaires.<\/p>\n<p><strong>Security benefit:<\/strong> Change management, incident response, business continuity create operational resilience beyond payment security.<\/p>\n<h3>Compliance Automation<\/h3>\n<p>Infrastructure as Code (Terraform, Ansible) maintains version-controlled configs. Prevents drift, enforces baselines automatically. Automated scanning identifies deviations before they become violations. Continuous audit readiness beats scrambling during audits.<\/p>\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-23089\" src=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041615.jpeg\" alt=\"Dedicated_server_security_visual\" width=\"1376\" height=\"768\" srcset=\"https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041615.jpeg 1376w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041615-300x167.jpeg 300w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041615-1024x572.jpeg 1024w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041615-768x429.jpeg 768w, https:\/\/atalnetworks.com\/wp-content\/uploads\/2025\/04\/Dedicated_server_security_visual\u2026_202605041615-18x10.jpeg 18w\" sizes=\"(max-width: 1376px) 100vw, 1376px\" \/><\/h2>\n<h2 id=\"incident-response\">Incident Response: When Attackers Get In<\/h2>\n<h3>Preparation<\/h3>\n<ul>\n<li><strong>IR team:<\/strong> Defined roles for detection, containment, recovery, communications<\/li>\n<li><strong>Forensic tools ready:<\/strong> Memory capture, packet analyzers, file integrity tools<\/li>\n<li><strong>Quarterly tabletop exercises:<\/strong> Practice procedures, identify gaps<\/li>\n<\/ul>\n<h3>Detection &amp; Analysis<\/h3>\n<ul>\n<li><strong>SIEM alerts<\/strong> trigger investigations<\/li>\n<li><strong>Scope determination:<\/strong> Which systems? What data? How long?<\/li>\n<li><strong>Timeline reconstruction:<\/strong> When did compromise occur? What did attackers do?<\/li>\n<\/ul>\n<h3>Containment &amp; Eradication<\/h3>\n<ul>\n<li><strong>Isolate<\/strong> affected systems (prevent spread, preserve evidence)<\/li>\n<li><strong>Remove<\/strong> all attacker access (backdoors, accounts, credentials)<\/li>\n<li><strong>Root cause analysis:<\/strong> How did they get in?<\/li>\n<\/ul>\n<h3>Recovery &amp; Lessons<\/h3>\n<ul>\n<li><strong>Restore<\/strong> from clean backups after verifying complete removal<\/li>\n<li><strong>Post-incident review:<\/strong> Document what happened, improve procedures<\/li>\n<li><strong>Implement lessons:<\/strong> Close gaps revealed by incident<\/li>\n<\/ul>\n<h3>Business Continuity<\/h3>\n<p><strong>RTO:<\/strong> How fast must you recover? Different systems = different RTOs. <strong>RPO:<\/strong> Maximum data loss tolerance. Drives backup frequency. <strong>Failover procedures:<\/strong> Rapid transition to secondary systems. <strong>Communication plans:<\/strong> Keep stakeholders informed during disruptions.<\/p>\n<h2 id=\"atal-foundation\">Atal Networks Security Foundation<\/h2>\n<p>Infrastructure-level security support:<\/p>\n<p><strong>Physical:<\/strong> Tier-4 data centers, 24\/7 monitoring, biometric access, ISO certified.<\/p>\n<p><strong>Network:<\/strong> 40 Gbit\/s DDoS (always-on), multihomed BGP (100% redundancy), private network options.<\/p>\n<p><strong>Hardware:<\/strong> Premium Dell with TPM, secure boot, IPMI management, hardware RAID.<\/p>\n<p><strong>Compliance:<\/strong> GDPR-compliant data centers (213 locations), data residency options, 99.99% uptime SLA.<\/p>\n<p><strong>Support:<\/strong> Free migration, 24\/7 expert support (real engineers), security consultation.<\/p>\n<p>We provide secure infrastructure foundation. You handle application\/OS security. Together: complete protection.<\/p>\n<p>Explorar <a href=\"https:\/\/atalnetworks.com\/es\/dedicated-servers\/\">dedicated server plans<\/a> o <a href=\"https:\/\/atalnetworks.com\/es\/contact-us\/\">contact our team<\/a> for security consultation.<\/p>\n<h2 id=\"faq\">PREGUNTAS FRECUENTES<\/h2>\n<p><strong>What&#8217;s the ROI of server security in 2026?<\/strong><\/p>\n<p>Average breach costs $4.2M. GDPR fines reach \u20ac20M. Compare against security investments: EDR $50-$150\/endpoint annually, pentesting $3K-$15K quarterly. Small org investing $25K annually protects against multimillion-dollar losses. Organizations with tested IR plans pay 60% less in ransoms. ROI is clear\u2014prevention costs less than recovery.<\/p>\n<p><strong>How do I know if I&#8217;m already compromised?<\/strong><\/p>\n<p>Indicators: unexpected outbound connections, unexplained CPU\/memory spikes, failed auth from unknown IPs, new user accounts, modified system files, unusual cron jobs, unrecognized processes. Implement SIEM for automated analysis. Multiple indicators simultaneously = assume compromise, initiate IR.<\/p>\n<p><strong>Should I pay ransoms?<\/strong><\/p>\n<p>No. Doesn&#8217;t guarantee decryption. Funds future attacks. May violate <a href=\"https:\/\/home.treasury.gov\/policy-issues\/office-of-foreign-assets-control-sanctions-programs-and-information\" target=\"_blank\" rel=\"noopener\">OFAC sanctions<\/a>. Recovery from backups costs less. Average Q1 2026 payment: $4.2M. Organizations with tested backups\/IR recover for &lt;$100K.<\/p>\n<p><strong>Which compliance applies to me?<\/strong><\/p>\n<p>GDPR = EU residents&#8217; personal data. HIPAA = US healthcare providers\/business associates. PCI DSS = payment card data. SOC 2 = service organizations (not legally mandated). Many need multiple. Consult compliance specialists for your situation.<\/p>\n<p><strong>Can I secure servers without a security team?<\/strong><\/p>\n<p>Basic hardening (SSH, firewall, patches) = yes. Advanced monitoring\/response = requires expertise. Options: hire specialists (expensive), use managed security services (cost-effective), or accept higher risk with basics. For sensitive data\/regulated industries, managed services often better than building internal expertise. Check <a href=\"https:\/\/atalnetworks.com\/es\/#pricing\">Atal managed services<\/a>.<\/p>\n<p><strong>How long to properly secure a server?<\/strong><\/p>\n<p>Initial hardening: 4-6 hours. Full implementation (logging, monitoring, backup testing, IR docs): 2-3 weeks. Ongoing: continuous process\u2014weekly scans, monthly reviews, quarterly pentests. Security degrades without maintenance. Budget ongoing time or use managed services.<\/p>\n<p><strong>Dedicated vs. cloud security?<\/strong><\/p>\n<p>Cloud = shared responsibility. Provider secures infrastructure, you secure apps\/data. Dedicated = you secure everything. More control enables custom implementations but requires expertise across all layers. Cloud provides built-in tools; dedicated requires manual implementation. Advantage: complete control. Challenge: operational responsibility.<\/p>\n<p><strong>How to prove security for audits?<\/strong><\/p>\n<p>Documentation needed: security policies, configs, change logs, access matrices, scan results, pentest reports, IR plans, backup logs, training records. Automated compliance tools continuously collect evidence. IaC provides version-controlled configs. Centralized logging with tamper-proof storage creates audit trails. Collect evidence from day one, not retroactively during audits.<\/p>\n<h2 id=\"building-security\">Building Security That Survives<\/h2>\n<p>The threat landscape won&#8217;t improve. AI attacks continue compressing windows. Ransomware groups refine tactics. Compliance tightens.<\/p>\n<p>Organizations succeeding share traits: Security as a continuous process, not an annual checkbox. Assume breach, optimize detection + response. Defense in depth, multiple layers. Test procedures before emergencies.<\/p>\n<p>Investment is real but manageable. Comprehensive security costs less than single breaches. Org investing $50K annually (EDR, scanning, pentesting, backups, training) protects against multimillion-dollar losses. ROI favors prevention overwhelmingly.<\/p>\n<h2 id=\"take-action\">Take Action Today<\/h2>\n<ol>\n<li><strong>Audit<\/strong> using this guide as checklist<\/li>\n<li><strong>Implement<\/strong> foundation: SSH hardening, firewall, automated patches<\/li>\n<li><strong>Enable<\/strong> monitoring: SIEM, automated alerts<\/li>\n<li><strong>Test<\/strong> backups this week<\/li>\n<li><strong>Document<\/strong> IR procedures before incidents<\/li>\n<\/ol>\n<h2 id=\"deploy-infrastructure\">Deploy Secure Infrastructure<\/h2>\n<p>Atal Networks provides infrastructure foundation for your security strategy. Our <a href=\"https:\/\/atalnetworks.com\/es\/dedicated-servers\/\">Servidores dedicados<\/a> combine performance, control, infrastructure-level security\u201440 Gbit\/s DDoS included, 99.99% uptime, Tier-4 data centers, 24\/7 expert support.<\/p>\n<p><strong>Ready for secure dedicated servers?<\/strong><\/p>\n<p><a href=\"https:\/\/atalnetworks.com\/es\/dedicated-servers\/\"><strong>Get Started \u2192<\/strong><\/a> | <a href=\"https:\/\/atalnetworks.com\/es\/contact-us\/\"><strong>Contact Security Team \u2192<\/strong><\/a><\/p>\n<p>Limited-time discount for new clients. Enterprise infrastructure supporting your security requirements.<\/p>\n<p><em>Current as of April 2026. Security is continuous\u2014subscribe to <a href=\"https:\/\/www.cisa.gov\/\" target=\"_blank\" rel=\"noopener\">CISA<\/a>, <a href=\"https:\/\/www.nist.gov\/cyberframework\" target=\"_blank\" rel=\"noopener\">NIST<\/a>, and industry advisories for emerging threats.<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Q1 2026 saw 1,138 ransomware attacks across the Americas with average payments hitting $4.2 million\u2014up 38% from 2025. AI-enhanced ransomware [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":23080,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[1],"tags":[],"class_list":["post-23072","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-grade-server"],"acf":[],"_links":{"self":[{"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/posts\/23072","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/comments?post=23072"}],"version-history":[{"count":9,"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/posts\/23072\/revisions"}],"predecessor-version":[{"id":23275,"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/posts\/23072\/revisions\/23275"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/media\/23080"}],"wp:attachment":[{"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/media?parent=23072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/categories?post=23072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/atalnetworks.com\/es\/wp-json\/wp\/v2\/tags?post=23072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}