I know of no way to protect it by subnext, but if all the computers are on a LAN you could just make it a lan server (iirc it restricts it to the current subnet automatically when you run a lan server).
If all else fails, you could set a server password with the sv_password variable in the server configs and then have everybody create/edit their autoexec.cfg to have a line set password to the same as you set sv_password on the server.