If you haven't already, get fail2ban setup on the box to slow down all the attacks. And disable password login and switch to certs instead.
In my opinion less is better. RSA/4096-bit key encryption only. I don't even care if you use the root user. The ability for someone to crack a 4096-bit key is impossible in practice, and if your SSH server has a bug then it doesn't matter what fancy things you have setup.
Specially to look at successful logins and audit where they come from. This is a good blog post on the subject:
https://blog.sucuri.net/2016/03/server-security-anomaly-beha...
In the case of key-based-auth only, fail2ban is pointless.