The way in is usually mundane
Most compromised business websites are not individually targeted. Automated scripts scan the web for known problems in unmaintained plugins and themes, or try credentials leaked from elsewhere.
That is why the effective defences are unexciting: keep components updated, remove what you do not use, use strong unique passwords with two-factor authentication, and keep tested backups.
