10
That's a very good question.
There must be a few ways to secure it. One I can think of is - if you are not serving an XML in the web site - to change the MIME type of the XML registered against the web site so that it is not served.
Other solutions not directly securing the "hibernate.cfg.xml" file:
1) Define the configuration in web.config using NHibernate section handler
2) Configure in the code
3) Setup NHibernate to read a file with .config extension