See what you are saying but temper it with this.

User opened a zip file from an email then tried to execute the enclosed executable (.scr) file.

User is software programmer, many years experience, local admin on his pc, trusted and one of the last people I was watching for some "I didn't think!", mistake. I asked him why he tried to execute the windows file in the email and his response "to see what happened" a part of me responsible for security issues packed it's bags said "fuck this" and left at that stage.

The attack that will most likely get us will be from the direction we are not watching.

