Can a company dramatically reduce its network security threats from employees and increase overall company security at the same time? I believe that this can be done and isn't as hard as some would think it to be or should be, but Before I totally get there I want to discuss some of the other side as well. It seems that some network security practices could be comparative to how forum trolls are handled, the current methods don't work so well. For instance if john the janitor finds the network admins passwords in the trash and tries to bring it up to management and gets fired for it.