How can i protect agains incomming hackers?

Dear Piwik,

The last few months I have hacking activity on my website. From defacing the homepage to fake DHL scrips.
If I look in the Securi plugin logs I see this.

juli 29, 2015 9:58 am system ::1 New file added: (multiple entries):

•.htaccess (size: 395483)
•0x3a.php (size: 2424)


Does this mean Piwik is the weakest link in my secutiy or could the leak be anywhere? Maybe I did the installation not the right way?

Could you give me some tips how to protect myself against these attacks.