NinjaFirewall won't help you! People think plugins will save their ass in all of time, and that isn't true. Plugins is a opened door to hackers using exploits, vulnerabilities, bugs that can do your website being hacked.
Remember one thing, the best security is on backend. What I mean with "backend"? I mean, the security and hardening you should do is on the server. If you are using VPS/Dedicated server, is that you should take measures to improve security on your website.
You can use ALL Plugins, that won't prevent your website being hacked. Is the reverse, it open a door to exploits, bugs and hackers use it in their favor.
Cloudflare can help you, but is limited. Sucuri Firewall, BitNinja is a good choice if you don't have knowledge / know-how.
God! Finally someone that understands about security. Wordpress Plugins especially "Security Plugins" is dangerous, and if is not used with moderation, can be a big problem.
I recommend hardening the server that's what will prevent your website being hacked. Hardening is the best you can do.
For example using ModSecurity Rules, IPTables, fail2ban or SSHGuard.
Naxsi WAF for Nginx web server (A huge improvement of Security) also with CDN.