...admin users that can use sudo? Is this all done manually?
Maybe add TOTP to local admin users, too
Restrict SSH even more, e.g. via this hardening guide.
SSH only from management lan via SSH config or via Firewall? This is not very clear in the document.
SIEM is good, but AFAIK there is no...