The majority of the "big" hacks are done by getting passwords through social engineering (a phone call from "support" needing your password...a test found that more than half of several companies' users would be willing to give up their logins for gifts!). If your passwords are secure, and your computer doesn't have any keyloggers or other "viruses" you'll be fine. If you are on a shared hosting plan, then your site can only be as secure as their servers. If their server passwords get compromised, then nobody on the server is safe.
Rule #1: Never use "admin" or your own name as a username - after all, the username is half of your login! I have a link to a password-generating tool on my browser's toolbar,
http://strongpasswordgenerator.com/, and it can be used for both usernames and passwords.
Rule #2: Never have an "option" you don't need, or a script that you don't use hanging around on the server. One of the earlier vulnerabilities on MODx 1.x was .php files for the code used in snippets - it was fairly standard to have the actual snippet code in a file like "ajaxsearch.snippet.php" in the assets/snippets/snippetname/ directory. A more recent issue involved the "forgot password" link on the Manager login form. None of my sites were vulnerable to that because I always removed that link from my Manager login forms; now I just disallow the feature in the System Settings.