We've been suggesting the following, after seeing attacks on the same /24 subnet (scanning networks)
We now scan nightly and send out instructions on how to close your open NTP server or DNS resolver should you have one, a lot of PBX distributions come with NTP open by default.
Start by...