Blocking zip's in general will definitely be a problem.
So, the best practice is to add custom rulesets. I'll try that. Main fear is that Locky might pass through somehow, break havok on network shares and tape storage will not work for some reason...
EDIT: Actually, the sanesecurity foxhole_generic.cdb ruleset seems perfect for what I am looking for, which blocks "double extensions of certain dangerous filetypes that are contained within Zip, Rar, 7Zip, Arj and Cab files. These files will be detected only if they end in dangerous filestypes such as: pif, scr, exe, com, bat, cmd, vbs, lnk, cpl and vb."
This way, archives are not blocked in general (they shouldn't need to).
Has anyone managed to integrate them to SME?