1- Kerberos : Kerberos is mandatory for prod environments, you can either use your AD embeded kerberos or install a new dedicated KDC - Kerberos must be in HA
Risk not doing the above : User impersonation for the services accounts ( jobs can be exported to run as super user permission )
2 - Use a firewall to block all inbound traffic to the cluster- all sources / all ports except from the edge node ( Gateway )
Risk not doing the above : Passwords in the wrong hands will systematically give access to the cluster