One of the smartest security guys I ever knew once said “It’s about the endpoint stupid.” Now that part about stupid was rhetorical, not directed at me. I think. But what he meant was that the most important things to protect were the endpoints. Not that other parts shouldn’t be protected, but that the endpoints were the critical pieces. And recent facts have backed him up.
Look at the latest ISTR numbers. In 2009 four out of the top five targeted vulnerabilities were client-side vulnerabilities. The largest cause of breaches in 2009 were lost or stolen endpoints (laptops in this case). And even when information was stolen via hacking, the hacker was targeting the endpoints. It’s much easier to get inside an organization by planting malware on a client system, then to attack a well guarded server or break through a firewall. And if the Hydraq attacks...