CIO Brief: Attackers Adapt When You Block Macros
Retrospective: this article looks back at events from June 2022, written in 2026 with the benefit of hindsight.
The short version: For years, the main defense against malicious Office documents was blocking macros. In 2022, attackers used a new flaw, Follina, to run code from Word documents without any macros. Attackers adapt to every defense — so relying on a single control isn't enough.
Why layered defenses matter
When Microsoft began blocking macros in documents from the internet, it was a big win. Attackers immediately shifted to other techniques: new vulnerabilities, other file types, different ways of tricking users. Organizations with only one layer of protection were exposed again.
Layers that work together
- Email filtering that inspects attachments before delivery.
- Endpoint rules that stop Office apps from launching programs — regardless of the method.
- Fast patching for actively exploited vulnerabilities.
- Endpoint detection and response to catch what gets through.
- User reporting of suspicious emails.
Questions to ask your team
- Do we have endpoint rules that block Office from launching other programs?
- How quickly did we patch Follina?
- Do we test whether malicious attachments reach users?
What good looks like
Multiple independent layers, each covering gaps in the others, and regular testing.
The decision
Ask your team which single control, if it failed, would leave you most exposed. Then fund another layer behind it.
- Follina (May–June 2022): Office Documents That Ran Code Without Macros Incident Teardowns
- How to Configure Attack Surface Reduction Rules in Defender for Endpoint How-To & Hardening
- Detecting Office Document Exploitation: Defender XDR and Sentinel Hunting Queries Detection & Response