After X attempts to log in, it bans the IP address.
It will scan your wordpress files and alert you if any of them have changed in suspicious ways (hacked).
It can disable the xml-rpc endpoint which is rarely used and is a big vector for hacking.
… and a lot more but those are the main ones for me.
I use my searxng instance several times a day.
DNS server/cache/pihole. If that goes down I can’t browse anything.
I also selfhost a SaaS that I built. It’s essential to me that it’s available to my customers although I don’t use it personally.