Hardening a system (disabling unnecessary processes, PROPERLY configuring the firewall for inbound & outbound, etc) is more important than patching (you don't need to patch the server service if it isn't there)... least important is AV. Most important is user education.
A properly hardened system with a user who is aware of how to safely use the computer is by far the best scenario.
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



