You basically need to employ network engineering level security - very tight firewall rules, use NAT where it’s available (IPv6 removes NAT, which ipv6 apologists will tell you is a good thing - they’re wrong, as it removes per-service level control and moves it out to per-device/per-NIC), and punch very specific holes to grant access where needed.
It’s not the knitting projects at home or shooting cans in the woods people have an issue with, it’s the legislature you vote for, the way you treat people when you’re not at home, and the kinds of people you support (people in aggressive positions of authority)