1. Educate your users 2.Identify your primary security contact 3.Secure employee systems (including staying current on latest browsers) 4.Implement IP restrictions 5.Strengthen password requirements 6.Require secure sessions 7.Decreased session timeouts 8.Consider 2factor authentication (RSA token plus user name/pass word), Contact SFDC for help