people don't take any of them into account in the course of presenting their company's site to the public.
You probably have heard this advice before, but it applies here equally. Don't choose a common password such as "password," "123456," or "football." Choose a much more secure password, that mixes upper-case letters, lower-case letters, numerals, and even symbols (!$#%&*), that will be very difficult to guess or decipher.
WordPress will even let you install an extra plug-in, such as BruteProtect, to prevent more than a certain number of login attempts. It will keep track of IP addresses of all login locations, and can automatically block logins from specific locations if the number of attempts is too high—which can happen with "bot" attacks.
We recommend using a password manager such as 1 Password or Last Pass. A password management program to keep track of passwords and to create secure random password.
Some plug-ins are not updated regularly, or at all, so always be aware how current the versions are that you're using, and keep on top of plug-in developers to see if they are still actively supporting their plug-ins. If not, question yourself whether you really need to use them, or if there's a way you can substitute a more current alternative. Fewer plug-ins are better than many.
Always keep a secure backup of your site and its content, preferably in a different location (or in the cloud) than the original data. WordPress itself allows you to create a backup, using a free or paid option to do so. But you should also perform your own personal backups. There are plug-ins that will export your data to services like DropBox, and there is a great backup tutorial located in the WP Codex. It's a good idea to do backups before upgrading, as well (see the previous step, above).
Beyond the plug-ins mentioned in the above steps, there are many that focus specifically on security. Extensions, such as WordFence, Sucuri, All-in-One WP Security, and iThemes Security, can track all the changes on your site (including those made to plug-ins), scan your WP files for irregularities, hide login pages, and remove crucial information that hackers look for when they try to gain access. It's worth it to do some research to see which plug-ins provide the security you desire, and which are the most cost-effective. Look for reviews online of the ones you think will be most beneficial.
You're not the only one concerned with protecting a WP site, and there are many companies now providing valuable solutions to give you the requisite peace of mind regarding this issue.