1. firewall - only allow SSH connections from trusted static IPs
2. Use SSH keys then disable password logins. Lots of guides online to create keys, so I'll just cover the 2nd point: as root or sudo, edit /etc/ssh/sshd_config
PasswordAuthentication no
ChallengeResponseAuthentication no
# restart sshd
(edit: make sure the SSH keys have passphrases. That way you have an extra bit of security in case any workstations get compromised)3. Disable root access. edit /etc/ssh/sshd_config
PermitRootLogin no
# restart sshd
4. Limit SSH access to specific user accounts. This prevents users creating their own key (in the case of mountable home directories) or other machine accounts with passwords (if you've not done #2): groupadd sshaccess
# add all users to the sshaccess group. lots of different ways to do this. The following will work on some flavours of Linux but not all:
usermod -a -G sshaccess $USER
# now edit /etc/ssh/sshd_config and add the following in (it wont already exist)
AllowGroups sshaccess
# restart sshd
5. Install auto-firewalling for failed SSH logins. I personally favour fail2ban as that covers other scenarios too, but I've also used denyhosts and that's worked well for SSH.6. Lastly, and by far the best option, don't enable SSH on any internet facing IPs.
If you need SFTP enabled, then let me know and I'll post some details on how to harden SFTP so attackers cannot gain an SSH shell.