You need just authenticated SMTP, as do I, for precisely the same reasons.
Is there a policy statement on this - you have authenticated POP3 and you manage that well enough... how about authenticated SMTP? It would be very easy to prevent abuse of it. If BT can manage it, you guys should be able to do it in yer coffee break...