Simple solution what I'm using is changing web port in IP/SERVICES/WWW
If you put some other port, for example 8282... only who know that can access to your graphs
But also anyone can test the machine for open ports, find this, and this way gaining access to the web interface also. Or, by knowing this, erase the /graphs
at the end of the url. And the same result. With login and the rest.