Hi
Local encryption and password protected ID are OK.
Even when an attacker has access to the server and copies everything on os level, the db's will only be accessible with the server.id.
Keeping in mind that bruteforce attacks are quite fast today, the id's password should be quite long.
Drive encryption prevents only the case, when an attacker pulls out your servers HD or boots your server from a different OS and tries to image your HD.
You should also think about your notes clients. They should also be enforced to encrypt local replicas. As the chance that someone gains access to a client are a bit higher.