On top of the security plugin, I added an .htaccess rule to only allow access to the admin login and the entire wp-admin subfolder from within their office. They have a static IP and were OK with only having access from within the office so this worked well for them. This pretty much ended all of the attacks. I probably wouldn't rely on this as the only protection, but it definitely has been a great piece of their overall security plan. The code to do that is here: