We migrated an stalled self-made from a client to WP 1 year ago.
He told us that in 10 years of life of his site, he had a 100% of uptime, 0 hacks 0 issues
And 0 content changes.
Now he was willing to feed a blog, and event calendar and many other things that WP solved with ease.
But in the past year he had two massive downtimes due to attacks. The page had good reputation before the migration, and the attacks were extremely frequent as yours. One DDoS attack and a vulnerability in a redirect plugin were the two weak points during this year.
Why he could stand for 10 years without issues and in 1 year is having a lot of issues?
Because WP gives a lot of cheap or free features which being self coded may cost several thousands of $ but at the same time, those features, mostly open in code to attackers are susceptible of being exploited at some point + a WP core which is also susceptible to other exploits that may cause issues.
Before this client had an almost static site with a self-coded code base.
Now he has an organic site with a zillion of opportunities to expand
Want to secure your WP like a stronghold? Go Static with plugins like WP2Static. 10 years, 20 years, 100 years and your site will be up and running flawlessly.
Need dynamic data while being relatively secure? Then spend $2-3-10K and code yourself what you can obtain in WP for, at most, $100 a year. So asking for another $100 in WP monthly maintenance (at least, means at worst $1-1.5K/year) for securing a WP Site up and running (or the equivalent in time)
But WP is not a set and forget system.
There must be done constantly security checks, updates and even some automated and simple e2e testing if you have the tools to be sure that your sites will keep up and running and detect issues as soon as possible.