The real think that 's saved you is to have backups not too old. Zfs is unable to check if data is rewrited by unallowed user.
Theoricaly, youu server isn't publicly displayed, so no really need to lock the public IP.
But, you need to allow only by mac address, and disable password...