Limit root (and any other SUPER-privileged user) to
GRANT ... TO root@localhost ...
That prevents access from other servers. You should hand out SUPER to very few people, and they should be aware of their responsibility. The application should not have SUPER.
Limit application logins to the one...