As the founder of teclada.com, I'll also share that one of the biggest risks is not even technical but human:
- not managing your SSH keys properly
- not even knowing where they are
- reuse, copying, etc
- forgotten placement of keys in authorized_keys
And worst of all: - "no way I'm going to even consider changing any of it"
- "our audit logs are .bash_history"
¯\_(ツ)_/¯