OpenBSD firewall up to date and active... check.
Apache patched and current... check.
Apache running as non-root user... check.

OpenBSD in use on web server and up to date... check.
PHP patched... check.
Passwords stronger than hell... check.
Bring it on.

"Seriously..." I'm not all the worried. They only sites targetted are going to be big, like Google, Yahoo and the likes.