Keeping the system up to date, disabling UPnP, disabling remote access, Strong Password, a good firewall (ex: PfSense, untangled) and Vlan should be a very good set up and minimise the threat. I also think NAS should be remain on the LAN and should be denied internet access.