I am setting up ISA server for our local network.

If I, only, allowed outgoing request, should I be
concerned that someone could steal files or packets of
data that travel internally or somebody could destroy the
installation? If it is the later, then I would mind a lot
less.

If it means that somebody could steal the data, would DMZ
setup resolve this problem?

I guess the question is: eventhough it is possible, is it
being done today?

If it is being done today, is there a solution?

Thanks in advance