I recently gave a presentation to the DC WordPress user's group on the five most common security mistakes I see WP users make. Slides are here, if you're interested in learning more:
https://www.slideshare.net/JasonLefkowitz1/dont-sabotage-your-wordpress-success-five-security-tips/
(And if you're in the DC or NYC areas, I can present on this subject to your group too; feel free to ping me for more info.)
PS many thanks to LinkedIn for buying Slideshare and turning it into a raging garbage fire