Rick has given some great suggestions 
I block a lot of spammy hot-spots. Sure, not all people from these blocked countries are dodgy. More often than not, the majority are infected PC/Servers and have been hijacked, and are part of a botnet. I have securities in place to log and instantly ban certain activities. I often see my WP login page getting hammered every minute, each attempted with a different IP spread across all corners of the globe.
Have other traps in place which send dodgy IP's to ProjectHoneyPot.org. Also have security which filters UA (user agent) indentifiers. You'd be surprised (or maybe not) the number of fake Google, Bing, Yahoo bots out there. This trap slaps them. On top of that, I'd dare say 99% are use outdate browsers. Seems FireFox 40.0 is popular lately. So I block all browser that are more than 3 major updates old - these days people's browser are generally updated automatically. If your still using an outdated browser, then your suss on my list.
I also block Tor browser, Tor network and, cloud servers. Places like Amazonaws etc. Also have a block for Cloud Flare. Basically anyone not accessing my sites from a ISP is awarded an instant block. Then people who access via a ISP are scrutinised against other fliters.
Yes I probably seem hyper paranoid to most webmasters. But, when your business is at stake, and so to your income, then I believe taking the right action to minimise the damage these scum bags can do, isn't overkill, instead, it's being smart 
To minimise scraping from Google cache etc, I've added:
Code:
<meta name="robots" content="noarchive" />
Since doing that last year, my scraped content has been drastically reduced.
Protecting my business from this crap, errodes into my work time. But, if I don't do it, then I'm at the mercy of these bastards!