Most malware: Unixes (Linux, BSD) probably not vulnerable, at least today
On well run systems we kill unneccessary services, install updates
Both spam and malware spreads via email, we do handle that
Packet filtering (firewalls) can be useful