1) Whitelist Lockdown your server. Once that is done: No unauthorized IPs will be able to access your server.
2) Set good passwords for all your sip accounts and user accounts. This helps in case of a failure of 1) (even temporarily).
3) SIP accounts should NOT be "100" through "10000". They should be alphanumeric. This only involves the "extension" field under admin->phones. It does not affect the dialplan or extensions.
4) Do use the instructions available here
http://viciwiki.com/index.php/DGG which include whitelist lockdown instructions. It also includes Dynamic Good Guys itself which is merely an add-on to allow easy addition of Authorized IPs and even a mobile link to self-add from outside the system. But that is not necessary, all you really need is the instructions for whitelisting.