First of all make sure you have the Wordfence plugin on your site and activated.
Then on your phone get a 2 factor authentification app, there are lots of different apps but all do the same thing so its just personal choice. I use Authy.
Google Authenticator
Or other appsĀ
In your WordPress dashboard go to Users, then under your user name hover and click 2FA
Using the app on your phone click the add website / + button on your phone app and then scan the code on the website on the left
Save it on your phone app
On the website download the recovery codes and save / print them – you will need these if you change phones / reinstall your phone etc
On the website add the code that will now appear on your phone and click activate