* Fine-grained segmentation of all networks on need-to-know basis, informed by the org chart and detailed role descriptions for virtually all employees.
* No employee access to arbitrary Internet sites
* For employees that require Internet access, air gaps between computers that can hit Google and computers that can access company email
* Formal audits for minor software releases
* Expensive, heavily tested secure coding training for all developers
* Adoption of secure coding/design standards ("this is the XYZcorp way to make an SQL query" and "this is the XYZcorp way to render HTML"). Strict bans on deprecated interfaces.
* Employee access to sensitive internal applications (like document and image management) gated through Citrix-like environments, so you have to remote terminal in to get to the browser that actually talks to the application.
* Extremely minimal access provided to VPN users.
* Total 8021x-style lockdown of network ports and fascist policies against bringing own devices.
And so on.
There is zero chance this is ever going to describe any huge company.
zomg! muh freedoms!
I've experienced this myself inside a major central bank. Most development staff were a) demoralised and b) frequently adopting insecure work-arounds.
Paranoia in excess.
About the closest I've come to seeing any of these bullets deployed reliably is Microsoft's developer training and deprecation of the standard C library, and that initiative was so out-of-the-ordinary that it was newsworthy, and widely reported.
But to actually earn that bullet, Microsoft would need to deploy those same measures across all its contractors, and, more importantly, deploy them on internal IT and line of business systems, not just the Windows and Office codebases.
Plus, the posts I read earlier didn't mention 'Fortune 500' or 'reliably' - and I'm glad you didn't use words like 'productive' and 'efficient'!
Either they need to sell my address to spammers to finance their business or they delusionally believe I want to read their spam.
That may be a realistic proposal, but I'm skeptical that it's the best answer, maybe because 100% of my Citrix experiences have been awful. Wouldn't "ensure internal app adhere to all other points, rewriting them if necessary" be a better answer for "given infinite money" question?
You'd still have Citrix lockdown environments for any application that you can't rewrite. For instance, an F500 might license the web app it uses for image management for things like scanned medical records.
I should add: I don't think any of these are realistic proposals.
That's not to say that user data should go unprotected; the majority of people in the company should have zero access to that, such that even if their systems were compromised user data would remain safe.
Swiss banks have a tradition of security overkill. Branches in nice areas have bulletproofing rarely seen in the US outside of very bad neighborhoods. It would be un-Swiss not to be prepared.
In that case every employee would have one or more security people standing behind them the whole day. No email would be opened without a phone call to the sender to confirm that it's not spear phishing.
But more realistically, loads and loads of 24/7 monitoring and internal auditing and testing. Attackers have to abuse something to get in, and if the company is internally doing the same thing with a large enough team, 99% is probably secure. Hackers will probably look for easier targets then. Still, this is quite unrealistic to happen in present times.