- Remove local admin rights from user’s accounts – the normal user accounts don't need local admin rights, if the normal users need to install any software, this will installed by your IT staff , the results, the malicious software will be reduced a lot.
- Patch regularly – patch at least month...
