I'm attending the BlackHat this year, and one of the most interesting and controversial talks so far was "SexyDefense - Maximizing the home-field advantage" by Iftach Ian Amit.
Ian opened with some very good advice about the defensive mindset: there is no final, optimal, best-practice security strategy. It's:
a) always evolving
b) specific to your organisation
The link for this article located at Sophos is no longer available.