Thanks for all the replies
Yeah, I do need it for outside use (I vnc in to my windows box from remote locations, sometimes from a physical PC, others from an android tablet). After reading a few replies I decided as a quick fix to change the port for the vnc. I like the idea of tunneling or VPN - I do a fair amount of networking and sheepishly admit I've only set up a handful of VPN's (none for myself though). Going to have to weigh the options and make sure both/either are readily usable by my existing methods (meaning android devices will still be able to 'get in'). Liked that serverwatch link though.
Thanks again for all the replies/comments/assistance. Feeling a lot better about the situation now