A VPN may or may not help to keep you from getting “hacked.” The main thing to do is to turn off WAN-side access. Also, change the port number and ensure HTTPS is required. Of course, what many folks describe as hacked starts from the “inside” (LAN-side.)
FWIW, here is a mini-write-up I did a few months ago regarding implementing ProtonVPN.