They seem to be okay w/ only HTTP ports being open on the server (80, 443). They "found that open ports can lead to cyber claims".
But yeah putting it behind some kind of VPN is advisable if anything because of all the driveby nuisance attacks on ipv4.