I am not a security expert but the conclusion I have come to is that it is next to impossible to prevent a truly determined attack against any network - at least while still maintaining some even half-way acceptable level of utility.

As you have said, the goal is to do enough so that you are not a target of opportunity.

