If you have high value assets and are being targeted, changing the SSH port number has virtually no effect on likelihood. Blocking port scans?
Great, they will pay someone in your org $500 for an .ssh/config. Or $5000.
Changing SSH port numbers and the other mechanisms in this article are so much bike shedding.
Do the hard work first. Implement multiple layers, patching, monitoring, thresholds for automatic disconnect, etc.
(Aside: why do you even think the president is in that convoy? They may well be elsewhere, moved into the third suburban at the last possible invisible moment.)