Yes, but it has to be balanced. Otherwise, if you take it to the extreme, you'd disconnect the Internet to maximise security. If security is so obstructive that it prevents the business from working, then it is useless. It adds no value to the business.
In this case, the traffic is expected, known, and understood. I'm guessing they don't host any MySQL databases onsite, so the risk is not to the company, but to remote companies hosting MySQL databases.