If someone got access to the CMS they could do alot of damage.
It would be handy to be able to restrict the CMS so it can only be accessed from say work and home and no-where else.
You could possibly have a white list of IP's.
This alongside only allowing strong passwords and enabling 2FA would make it as safe as it can be.
NB: This should be in the security section but it isnt in the drop down, not sure why.
Working on the basis even large IT systems get hacked, I'm in favour of having as many methods of protection as possible. Maybe I am over cautious but this system will contain a full list of your customers.
2FA is available on the CMS please contact support