The first thing I’d do is to build a threat model.
What kind of threats are you trying to protect against?
Drive-by exploits in the browser? Spearphishing? Software/hardware supply chain attacks? Those are just general examples.
What kind of threats are you trying to protect against?
Drive-by exploits in the browser? Spearphishing? Software/hardware supply chain attacks? Those are just general examples.