Patch on a schedule
Core, themes and plugins, checked weekly. The overwhelming majority of compromised sites were running a version with a published fix available for months.
Reduce what is exposed
Practical measures:
- Remove themes and plugins you do not use
- Disable file editing in the dashboard
- Enforce strong passwords and 2FA for admins
- Limit login attempts
Assume it will happen anyway
Keep off-server backups and know how to restore them. Recovery time is what turns a compromise into an inconvenience rather than a crisis.