When Jeff and the StackOverflow team were interviewed on Hanselminutes last fall, Scott was critical of some of the decisions that were made with respect to securing the StackOverflow servers.
My question is, what is the recommended approach to securing a website? Assuming I'm developing an ASP.Net application with a SQL Server database on a separate physical machine, what steps do I need to take to secure my environment from attacks?