In terms of hardware/OS: Turn off everything incoming except for HTTPS, SSH, and ping (optional). Make sure everyone uses SSH keys (no passwords)
In terms of programming, focus on security roles is tricky at first. So you want to be careful in describing how user roles or user permissions work in your site.
Create a staging server with test data that mimics your production site (nearly exactly). Any penetration company company will ask you to sign a "This won't hurt anything", when smashing up your server.
Another place to focus is how backups are copied, who can access the data, etc..
This is a really big topic. Your insurance company when you apply will have an excellent check list.