I think 2 good concepts come to mind to help you make choices:
Least privilege - Only give things/people just enough access/authority to get the job done. A good example is sonarr doesn't need access to your personal photos to do it's job, so don't give it access if to them.
Defense in layers - Nothing is perfect and you can make mistakes in configuration. Don't rely on a single point of failure to protect you. If you want remote access use a VPN. But also take steps in your network like putting a password on the logins.