One of the simplest, things to do on machines is to disable autoruns on all drives, a primary access method for malware. Teach users to delete any emails that they don't recognise, disable script and stick to plain text emails only.

The stupidity anmd cluelessness of this amazes me. All critical infrastructure should be on private networks with no direct access to the internet. Where access is needed, it should be via a single point, with firewalls and mail and attachment scanners that actually work. Those resposible for all this must be asleep at the wheel, unbelievable...

