Posts like this just make me realize how impossible it is to follow every security best practice and stay one step ahead of the latest techniques. You can maybe try tick the most common boxes, but expecting users to be able to police their machines, networks, and other attack surfaces (and still find time to get work done) is unrealistic, IMO. I'm starting to think the common factor here between secure systems and insecure ones is lucking out on having no interested / skilled attackers...