
Install the fix wordpress malware removal Firewall Plugin. This plugin investigates requests with WordPress-particular heuristics that are straightforward to recognize and quit attacks that are obvious.
Use strong passwords - Do what you can to use a strong password, alpha-numeric. Easy to remember This Site passwords are easy to guess!
For me it's a WordPress plugin. They're drop dead simple to install, have all the functions you need for a job like this, and are relatively cheap, especially when compared to having to hire someone to have this done for you.
Note that you should try this step for setups. You will also have to change of the table names within the database if you would like to get it done for existing installations.
However, I recommend that you set up the Login LockDown plugin in place of any.htaccess controls. That will stop login requests from being allowed from a specific IP address for an hour. You can get into your panel while away from your office, and yet you still have great protection against hackers if you do that.