I’'m attending the BlackHat this year, and one of the most interesting and controversial talks so far was "SexyDefense - Maximizing the home-field advantage" by Iftach Ian Amit.
Ian opened with some very good advice about the defensive mindset: there is no final, optimal, best-practice security strategy. It's:

a) always evolving
b) specific to your organisation

The link for this article located at Sophos is no longer available.