Most compromised sites fall to the same handful of causes. Cover these and you are ahead of nearly everyone:
- Keep the CMS, themes and plugins updated, and delete anything unused.
- Use strong, unique passwords and a password manager - never reuse your cPanel password on the site.
- Enable two-factor authentication on the client area and on your site's admin login.
- Install a security plugin (Wordfence or similar) with login attempt limits, and change the default admin username away from
admin. - Keep your own backup as well as ours, and test that you can restore it.
- Check cPanel → SSL/TLS Status and force HTTPS everywhere.