A good antivirus with a state-of-the-art anti-spam feature, running at the gateway, should be the first line of protection against spear-phishing. The company should run intrusion-detection mechanisms at the network perimeter. An approach that is more restrictive but yields the best results is whitelisting rather than blacklisting. This approach ensures that the user can`t physically visit a malicious URL even if they opened the spammy message and clicked it deliberately. The purpose is to gain extensive intelligence about the target, to make it bleed money.”]

