Make sure you have 2 factor authorization turned on. It will send you a text with a code when logging in. Also set a different, better password for the ability to send bitcoins out of the wallet. All of this can be found in the settings on the site.
I believe that you can get around having to use 2FA if you can get your hands on a backup of the encrypted wallet file. 2FA for blockchain.info is only specific to your identifier, if someone were to make a new identifier with your password and had your encrypted wallet file they could import your keys and spend your money