This is of course the most correct solution. But the thing is you can not fire a CFO.

InfoSec policies can be run pretty sharply when working in an corporate company, but in smaller companies, rules are obviously bent. Results are disasterous and IT guys get the blame for it.

In the end as you have spelled it correctly, we're cleaning virus everyday, trying the catch the backdoorers via registered MAC list...

Hopeless...My IPSEC Policy is still awaiting to be signed...