Make sure you have a secure SQL password and that your website is secured.
You can change sql password like this:
Go in Enterprise Manager and follow the images:
Also you need a good Firewall (I use Sygate Firewall Pro 5.0).
Make sure you block DataServer ports (those are blast ports...