Mophilly
While useful, banning senders is like chasing your own tail, it will always need to be done & re-done as spammers change IP's & locations etc.
Older users email addresses are generally far more widespread amongst other people, so the chances of other peoples address books being compromised/harvested increases, the longer a person/email address has been around.
Have you enabled executable content filtering in server manager Email panel ?
Obviously this will block messages with certain enabled attachment types, but if you can tolerate that, you will find a big reduction in spam & virus laden messages.
I get senders to send ZIP or other blocked attachments to an alternate external unpublished email account, or arrange for them to upload to the server, there are a number of contribs that will provide that functionality. Many common formats are still allowed through eg xls, doc, pdf, that do not have executable content.
Also is your SME server in server & gateway mode ? Better spam reduction is achieved in this mode.
What are the current RBL lists you have configured ?