Yes. If you run something sensitive, you should also consider:
- Invalidating any open sessions (i.e. cookies), since those could have been stolen.
- Force password changes for all users (since those could have been intercepted in memory)
- Change internal passwords.