Administrative web interfaces should only be accessible from specific IP addresses located on the internal network. You can implement this in a number of ways; however, using the following ModSecurity directive you can restrict the admin directory so it's accessible from your IP address only:

<Location /admin/>

SecFilterSelective REMOTE_ADDR "!^YOUR_IP_ADDRESS_HERE$" </Location>

Although ModSecurity can do great things to prevent intrusion attempts, it should not be seen as a security solution that will solve all of your problems. This means that your web server itself still needs to be configured securely to ensure that web application risks are minimized.

