we are hosting a couple of wordpress sites, they are all hacked all the time.
Well, Wordpress is full of vulnerabilities, that's true, but also quickly fixed if you know how to maintain it. Bigger problem is with plugins, they are often not so speedy with security hotfixes.
Also custom code that marketing agencies add are often pron to problems and they totally do not understand and underestimate security.
As I'd not like to recommend WP, still if you need to manage one from cybersec perspective you better hire some real-time vulnerability and high availability scanners that can help you find flaws quickly (I use F-Secure Radar and Site 24x7 simultaneously.
Additionally all the admin stuff starting from /wp-admin, backend apis and other backdoors known to the public are hidden via VPN as the server rule.
You cannot access them unless you break the VPN.
All together help me sleep and only gives me arguments to bash and hammer the agency and marketing and as I do own hosting environment at the company, I always backstab them saying that I'll switch it off and inform CEO about the hack unless they fix it in a minute.
Fortunately I can do it as CEO is on my side.. but if you don't have such mandate, you better find the way to discipline your marketing department and their digital partners by working policies and sole responsibility over app level of the CMS infra - contracturarily and with big penalties. That's where they sort of calm down and start cooperating better and thus creating your mandate of power when you manage CyberSec of those sites.
-h1
... Xerox Alto was the thing. Anything after we use is just a mere copy.
--- Mystic BBS v1.12 A48 (Linux/64)
* Origin: 2o fOr beeRS bbs>>>20ForBeers.com:1337 (21:2/150)