Do you have up to date RouterOS? Because if not, and you’d also happen to have WinBox port accessible from outside, then strong password is not enough:
http://forum.mikrotik.com/t/advisory-vulnerability-exploiting-the-winbox-port-solved/118771/1
And about blocking API, do you use it yourself? If not, simply disable the whole thing in IP->Services. If you need it, then limit access to selected IP addresses or networks, either in IP->Services or using firewall.