Good post Frank. Phishing is the #1 attack vector for a reason. Great points on hygiene. We see lots of opportunity to improve / limit admin rights across the mid market.

Have you thought about including the software supply chain attack phenom? Trusted applications (like Orion and VSA) with full network access gone bad are very difficult (impossible) to prevent but can be detected and stopped.

