From SSL, 2FA, and regular updates to server hardening, there’s a lot to consider. Which security measures have saved your community from attacks? Are some platforms inherently more secure than others, or is it all about implementation?
I enabled security features on my hosting service which helps to monitor for threats.
I only have one admin and that's me. Any other staff member is a moderator. There is no need for multiple admins aside from a tech admin if you must have one. I'd still create and require a contract for the admin to sign.
I use SSL like everyone else.
I keep a strong password and use 2FA for my account.
I'm super picky on adding new plugins. I try to keep that number down to a very low amount. Plugins = potential back doors.