You should enable a firewall to ensure that no one from the public Internet can reach any service other than the web service, and possibly a well-secured SSH server for administrative access. (For SSH, I recommend allowing public-key access only, and disabling authentication via password.)