- Always use keys and disable password based login
- Do not have ssh publicly exposed, or at the very least only via a bastion server, but if that bastion server is publicly available, then you are still quite vulnerable (perhaps even more so if someone gets into your bastion and is able to ssh to all the things if you are using key-based logins from the bastion)
- Always use a passphrase for your keys (helps with the “if someone breaks into your bastion scenario”)... but the best thing you can do is just don’t expose ssh to the public network