On the Enhanced Ongoing Services page we mention a long list of security measures and offer to bore you with it on request. This page is that list, because we think you should get to read it before anyone asks you to trust it.
First, the honest framing: WordPress powers something like half the web, which makes it the most attacked software on earth — and also the most defended. A neglected WordPress site is genuinely easy pickings. A properly hardened, properly updated one is a miserable target, and the difference between those two states isn’t luck. It’s a stack of specific, unglamorous measures, running every hour of every day.


