1) Dedicated router, secured and locked down. Nothing enabled that isn't required. All trading only done via that router. Go 3 deep if you want.
2) Dedicated laptop with Linux distro. BIOS password, encrypted hard drive and encrypted home folder. All trading is done on there. It is used for absolutely nothing else.
3) Everything is moved away from exchange after purchase via the above laptop alone.
4) Paper wallets are broken into three parts redundant ly. You can do this with a USB stick too. Thus to get the whole key you need all three pieces. This also protects your safety. If you can't make a transaction without say visiting your safety deposit box, then it's harder for someone to try and kidnap you to steal your stuff. Even more so if your the only signor for the deposit box.
5) Keep extra trezors or nanos with some balances. Keep one with you at all times. If someone targets you you can give it to them to get them to go away without losing substantial balances.
6) Keep multiple wallets for large amounts, don't keep all your stuff in one basket. If one wallet goes down you won't lose everything.
7) Use a clean smartphone in airplane mode that's dedicated for TFA.
8) Careful where you store you TFA backups. Keeping them in cloud or just on your PC is silly. A lot of people go all out doing everything else but will then store their TFA backups on their regular PC.
9) Enable all security features available on any exchanges you use. It's more work and time but we'll worth it.
10) Don't stay logged into an exchange when your away from and internet connected device. When your done on an exchange, log off! Shut Down your dedicate laptop.
11) Waddle from the hardcore HODL!