how do you "secure" machines if they are windows ones and dumb people plugin flash drives and click on big shiny download ram buttons. genuinely curious.
One way to do it is to whitelist all binaries in the system, and sandbox all applications (to prevent chances of a malicious PDF/image/etc abusing a buggy application).