- AWS
- EC2
- Tips
A Quickstart Guide to Securing Your EC2 Environment
Seven practical steps to harden EC2 instances, from IMDSv2 and Session Manager to encrypted volumes and private snapshots.
Nulink Security Team3 min read

Amazon EC2 gives you a great deal of flexibility and control, and with that comes responsibility. Under the shared responsibility model, AWS secures the hypervisor and hardware; everything from the operating system upwards is yours. These seven steps cover the most important ground.
1. Require IMDSv2
The instance metadata service hands out the temporary credentials of the instance's IAM role. Version 1 answers any request, which makes it a favourite target for server-side request forgery. Version 2 requires a session token, which blocks most of those attacks.
aws ec2 modify-instance-metadata-options \
--instance-id i-0123456789abcdef0 \
--http-tokens required \
--http-endpoint enabled
Set IMDSv2 as the default in your launch templates so new instances start secure.
2. Stop opening SSH and RDP to the internet
A security group rule allowing port 22 or 3389 from 0.0.0.0/0 will be found by automated scanners within minutes.
Use AWS Systems Manager Session Manager instead. It gives you shell access through the AWS console or CLI, with IAM-based access control and full session logging, and no inbound ports at all.
3. Use IAM roles, not stored keys
Never put access keys on an instance. Attach an IAM role through an instance profile and let the SDK pick up short-lived credentials automatically. Scope the role to what that workload needs and nothing more.
4. Encrypt EBS volumes by default
Turn on default encryption once per region and every new volume and snapshot is encrypted automatically:
aws ec2 enable-ebs-encryption-by-default --region eu-west-1
Existing unencrypted volumes need to be migrated by snapshotting, copying the snapshot with encryption, and restoring.
5. Keep snapshots and AMIs private
Public snapshots and AMIs can leak everything on the disk, including credentials and customer data. AWS lets you block public sharing at the account level for each region:
aws ec2 enable-snapshot-block-public-access --state block-all-sharing
aws ec2 enable-image-block-public-access --image-block-public-access-state block-new-sharing
6. Patch on a schedule
Unpatched operating systems remain a leading way in. Systems Manager Patch Manager can scan and patch fleets on a maintenance window you define, and report which instances are out of date.
7. Log network traffic
Enable VPC flow logs for the VPCs that host your instances. When you need to answer "what did this instance talk to?", flow logs are the record.
Check it continuously
Every item here is a configuration setting, which means it can drift. A new launch template without IMDSv2 or a quick debugging rule that opens SSH can undo the work.
Nulink Cloud checks these settings across every region and account on each scan, so an instance with IMDSv1 or a security group open to the world is flagged with its owner and a fix. For the view from outside, Exposure Management shows which of your hosts actually answer on SSH, RDP and other sensitive ports from the internet.
