Monitor bug reporting lists for browser and Operating System vulnerabilities that might offer exploit paths for spyware.
Configure safe ActiveX security settings.
Block Ad servers. Resolve domain names of known ad servers to 0.0.0.0 in a hosts file or at your DNS, or identify restricted sites in IE (see IE-SPYAD, above).
Add known Ad servers list in your firewall's blocked sites or WebBlocker denied sites lists on your firewall (Note: the list is very long so you may wish to start with the frequent and repugnant offenders).
Block potentially dangerous file types by content type (S/MIME type) at your firewall using HTTP-Proxy.
Stay informed. Visit some of the many valuable Spyware discussion and resource sites.