The only way to secure a windows server is to unplug the network cable
Seriously though, in addition to all the "OS" security recommendations (such as disabling anything that isn't necessary), make sure each person has their own logon/password, and it's changed on a regular basis. Also, make sure account cleanup for employees that depart is occurring. This will keep you out of trouble with audits. Regular virus definition updates is a must. Remote access via SecureID or something similar (though it's better to handle this as a network signon).
Most security can be handled via firewall/network rulesets. If someone can hack into a secure network through firewalls, etc, they have enough knowledge to hack the box.