1 - keep all things updated
http://wordpress.org/extend/plugins/...matic-upgrade/
2 - change admin username for something stronger with PHPMyAdmin, and use strong password
3 - use TAC as others said and security scan
http://wordpress.org/extend/plugins/wp-security-scan/
4 - don't use the fantastico WP installer... its sucks

5 - always RTFM!
