Hi,
there are a few things you have to do.
- Only enable Services really needed. Disable other services.
- Always make sure that you have the latest Security patches installed. This also applies for products which are NOT on the Microsoft list

. Usually it is no fault to run Windows Update once the week.
- use strong passwords for Administrative accounts.