Securing Hass.io?

I’ve been looking around, but must be looking in the wrong spots to find the answer to my question. I have Hass.io installed as a VM on my Proxmox server. It works fantastically, and I’m super impressed. I wish I would’ve jumped ship from Wink a LONG time ago.

So I set everything up, and I’m about ready to get my Nabu Casa account going. What do I need to do to make this thing secure? I kind of thought that I would want to password protect the ‘root’ account, but I haven’t found anything that indicated people were doing that. What about SMB shares, SSH, etc.? Do I run the risk of exposing that stuff to the internet when using the Nabu Casa method?

Thank you!