Probably all of this is known to Lounge operators, but Susan Bradley has posted this at Windows Secrets Newsletter (paid content, but the relevant parts can be seen by anyone) :
How to Protect Your WordPress Sites
http://windowssecrets.com/best-practices/how-to-protect-your-wordpress-sites/
Possibly interesting reading, with a good checklist.
(Paid subscribers can view the part about protecting ourselves as users of WordPress sites.)
-- rc primak