The problem is that if you're a multi-billion dollar firm, you likely have tens
of thousands of employees, the vast majority of whom are good little worker
drones who don't share your enthusiasm for keeping the network secure.

There's plenty of methods for mitigation, ranging from user training to
fascist locking down of the network portals to only registered MAC addresses
and forcing corporate-only control of the desktop via GPO - but none of
this *ensures* that your network won't fall victim. It only makes it less likely.

And at some point, your network has gotten fascist enough that the added
expense of adding more fascism exceeds the additional drop in likelyhood of
an incident.  When you hit this point of diminishing returns, it's time to
stop and go have a pint of Guinness at the London Underground(*)....

(*) Yes, there *is* a Guinness-and-darts pub in town called that, as many
SANS instructors can testify... :)

