At some point you really do need to give up on your fancy canaries, gateway and host IDS, perimeter blinky boxes, threat intelligence feeds, endpoint protection products, etc, and just start firing those in your employ who willfully and joyously thumb their noses at basic security hygiene.
You can't fix your security posture until you fix your update culture.
Until it's your top salesperson who 2x'd the quarterly revenue target... I'd like to live in a world where everyone knew basic security hygiene, but we have to teach it first, not punish.
> 8.2.4 Change user > passwords/passphrases at least once > every 90 days.
The consequences range in severity based on the number of times an employee is caught over a 12 month period, or if, as part of the attack, the employee enters their credentials on the webpage linked in the email (a big no-no). They range from: a meeting with your manager to discuss, a requirement to park outside the security gate and walk in for at least 2 weeks, to your vacation accrual rate being reduced, all the way to unpaid suspension or termination with 4 failures in 12 months.
Of course as part of the on-boarding process the company provides pretty extensive training on how to spot a phishing attempt but some attacks can still get a large portion of our company.
The downside is now some employees who have been burned before are terrified of opening any external emails. This ironically resulted in an exceptionally low participation rate in our company's annual employee engagement survey conducted by, you guessed it, an external party.
I think they have other mitigation strategies. Like probably quietly installing extra scanners on the email of the most "problematic" people who open anything and forward chain letters constantly.
In ancient times .exe were banned outright, and I have customers who also ban .zip. And a Word Doc with embedded macro is in effect an executable.
Accounts payable, for example, gets lots of these things as an expected part of the workflow, as does legal, and various parts of management.
PDFs have had problems of their own.
Many of the people that you most want to secure are the same people who need to be exposed to the outside world. CEO and CFO HAVE to deal with random people, as it's the job, but they are the most dangerous. If someone needs a 5 step verification process that takes days to communicate with your CEO, then you are not going to get may new clients or investors.
Everyone knows that to get the Macro to work, step one is to enable all macros.
The old approach, which I used, was to use a mix of desktop and embedded boards physically separated with a KVM switch plus controlled, sharing mechanism. Just keep the untrustworthy stuff on their own machines. It's klunky but a greater chance of working securely.