As the popularity of Zitadel increases, it is unfortunately likely to become an increasingly attractive target for attacks of all kinds.
If you host it yourself and only use it internally, you can of course limit access. If it is used as a pure backend service thanks to API, you could implement various security safeguards in preceding services.
However, I could imagine that there are some deployment scenarios that don't allow this so easily. Here, Zitadel should provide integrated mechanisms to prevent at least from a certain amount of background noise.