I don't see why it can be a security risk, as connection is via SSL and portal access has very limited admin access (user level).
Also I don't think there's a way to stop access as it uses same web port as https:443 for access inbound as micollab web services.
You can however control inbound connection from specific public IP's if you are in DMZ mode, but i suppose it'll be not be specifically to /portal but to the MiCollab services as a whole.
I will be very much interested if someone has a better answer.
Clever men learns what Wise men shares!