This is what I've done and I've had pretty good success.
* Build filter restricting 0, 1, 2, 3, 4 5, 6, 7, 8, & 9 and assign to Voice Mail ports. If you use remote notification or out dialing with your voice mail then build over rides for only the numbers you use and put in this filter
* If you do not use Pick Codes (101) then build a filter restricting 101 and assign to all Lines.
* If you do not use Pick Codes (101 dialing) or make International calls, make your Carrier aware of this and have them block it if possible.
* Remove all unassigned mailboxes
* Ensure employees change the manufacturer’s default password immediately upon being assigned a voicemail box.
* Train employees not to use easily-guessed passwords such as their phone numbers,
local number or simple number combinations.
* Should have users change mailbox passwords minimum every 90 days.
* Discuss possible use of Authorization codes with you provider.
* Work with provider for any other steps they can provide or suggest for you.