IMHO a misguided sense of 'prevention'
By far most spyware enters the system through scripted emails, and websites
boobytrapped with malicious ActiveX controls that download and install
themselves invisibly to the user.
If your company wants to prevent 'spyware' it would be time to start
investigating in web content filtering on proxy server level (ISA Server
2006 with content filtering extension(s) for example), or edge firewall
levels (think HOTbrick or similar appliance such as those made by
Symantec).
Stop it at the door, not in the livingroom.
Mind you that's not an excuse to not have decent antivirus running on your
desktops.