Password protect the AdminCP and ModCP directories with a different pass than the one you use for your forum user. That stops people from getting your forum pass and getting into AdminCP or ModCP and screwing over your site. I also password protect my includes directory. Make sure you Upgrade to 3.81 PL1. If you have root access to your server change your SSH and FTP ports to prevent possible DDoS attacks on them. Make sure your Database password is insanely strong and not easy for a hacker to "bruteforce". As some other people said "Do not make any hackers Mad". Also if you have a fair few people that don't like you i would pay UltimA and his Security Team to monitor your site.