Related question that has crossed my mind: what is this risk exposure of a linux server that is accessible via the internet that has port 22 enabled, and only has users with --disabled-password set (requiring ssh connection)?
As a follow up, what is increased benefit (if any) if port 22 is only accessible by a certain IP address (e.g. my home address)?