Send me an e-mail whenever someone logs in via SSH
Talking about this here, is this enough to prevent any damage (or more, being able to limit it through being notified of it) to your server should someone actually manage to log in?
Additional questions:
Are there other ways of intrusion you will not be notified of this way?
Should you log sessions additionally if you do not want to just scrape your whole server the moment someone breaks in?
How do you exactly figure out what made your server insecure?
EDIT:
It seems people have been half-reading the question and therefore giving unfitting answers and downvoting. First, the title has "emergency measure" in it, which means it is a measure for things being already too late. The backup plan IF things go wrong.
Second, "to scrape the entire server the moment someone breaks in" was also implying that. Should someone break in, in this case the entire server probably has to be thrown away and set up completely anew. So I am actually asking how to prevent that and what to do more in the case of an emergency - someone actually broke in.