Here's a really good article by Steve Bellovin and others from CERT that attempt to provide "risk management" instead of "risk avoidance"