What is the best way to secure an intranet website developed using PHP
from outside attacks?
The best way to secure it? Don't connect it to a network. Make your users physically enter a guarded room with a single console, running Mosaic.
Oh, you want it to be easy to use?
If you forget these simple rules, you could find your application starring on the front pages of newspapers everywhere, just like Yahoo mail.