Being “in the network” doesn’t matter anymore because everything has moved from unsecured intranet services to Internet exposed stuff authenticated with SAML. One user having malware is as much of a threat as someone else at the cafe having malware. No longer an issue.