We're migrating now pretty much because of POODLE so yes, FP2 is installed. The problem I'm facing is that I'm a designer not an admin and I'm certainly not a security expert. Nothing I've read tells me in plain English the worst thing that might happen if the server was attacked. The best I could get is 'not much'.
The server is read only, replication is one way push from inside our firewall to the outside, all access is via login, and all dbs are encrypted. The server is used only to display a subset of Notes docs to a subset of our customer base. My take on the issue is that we are at a very low risk level except for the fact that the various browsers are slowly refusing to connect to the server so an upgrade to the server was mandatory and we're switching from self-generated ssl certs to 'real' certs from external CAs.
Thanks for the reply, it is very much appreciated.