1. firewalling to only the sysadmin's IPs,
2. SSH keys + disabling password logins
6. and disabling SSH on internet facing IPs altogether (if possible).
1. firewalling to only the sysadmin's IPs,
2. SSH keys + disabling password logins
6. and disabling SSH on internet facing IPs altogether (if possible).