Allowing inbound ports

Is allowing the NEM inbound connections to your server/desktop a security risk (This is in relation to being a supernode). I was thinking of buying a server or desktop machine in order to use it solely as a supernode. I guess if my main account containing my XEM is on my laptop, I can dedicate the server to be a supernode, and then point my main acct to my supernode as a delegated harvester?

Which account do the 3M XEM need to go into, the main account on my laptop? If the server is compromised, I guess my XEM will still be safe.

The supernode only has the delegated private key in the config, the main account’s private key need not to be anywhere arround, neither on the supernode nor on your laptop. If the supernode gets compromised, your xem are still safe since the delegated account does not contain any xem.

Thanks BloodyRookie. Appreciate your help.