A few habits keep your account safe:
- Use a long, unique password for cPanel and change it if it's ever exposed. Update it under Password & Security.
- Enable two-factor authentication in cPanel for an extra login layer.
- Keep your CMS, themes, and plugins fully updated, and delete anything unused.
- Run Imunify360 scans and keep ModSecurity enabled.
- Set correct file permissions (typically 644 for files, 755 for folders) and never use 777.
- Remove unused FTP and email accounts, and use SFTP/FTPS where possible.
- Keep recent backups so you can recover quickly.
Also protect your client area login, since that controls billing and domains. If you spot anything suspicious, open a ticket.