You can tell Win9x not to use memory beyond the 512 MB barrier (I'll have to look this up if needed, something with MaxPage... in system.ini).
Win9x out of the box did not run -any- services that could be compromised with just a network connection. If you don't install the file server and don't use anything opening a port, you don't actually need a firewall (though I'd advise to install one anyway).
Of course security can very easily be compromised by using IE without necessary patches. Since IE has known vulnerabilities that can't be patched yet (that's probably not gonna change ever...), it's much wiser to use a 'proper' browser, e.g. Firefox.