Implementing WordPress security best practices requires additional security plugins. Plugins that force you to follow best practices, like two-step authentication, HTTPS/SSL, file permissions, password complexity, and others. They also protect you from brute force attacks.