A strong password that is unique to the account is incredibly effective. Be careful to not provide it to some look-alike site at www.outlook.fakesite.com for example. If you use an email client like Outlook or Mail or Thunderbird and your ISP / email provider supports SSL, then configure your client to use it. Other than that, it's up to your provider to keep their systems secure.
Encryption is important, which is why every single online retailer in the world utilizes it when they take your credit card information, and why many sites use it when taking your username and password. With the latest round of donations, I'm going to buy a 3 year SSL certificate for atxommunity.com.
Yes, I did check the email headers to see where they came from. The actual addresses were registered to this forum. They get into the account and send emails to everyone in the contact list. The same thing happened to my mom a few years ago, and once they were done extracting everything they wanted from the account, they deleted every email and contact so she couldn't easily warn everyone of the intrusion.