I often see website backups made only to the same server where the site is hosted.
What happens if the server goes down? Yes, you’ve guessed it, no backup.
Make sure your backup is hosted securely elsewhere.
Check your username
It's vital to stop using generic usernames such as "admin", "administrator", "root" or "test". These are currently heavily targeted by hacker's bots. If your WordPress username is generic, like "admin", you've given away half of your login details. If you are using one of these, set up a new admin account, login with that and delete the poorly named account.


