Presumably the Cumulus machine is inside your local network. So your primary defense should be the firewall between your internal network and the internet.
That firewall can take many forms, but for many the firewall is built into the gateway/modem/router that your internet provider typically bundles into your monthly bill. Of course, you can add additional systems behind that bundled box.
One thing you could do is run CumulusMX on a Linux box. Of course, Linux boxes can be hacked too, but the odds are that Windows boxes are a more likely hacker target. And, there is a pre-built CumulusMX 'image' for a Raspberry Pi (linux) available, which makes it a bit easier to install.