Just so I understand, Geo blocking can lead to false positives so I should never use it?
So then,
IPS can lead to false positives, so I should never use it?
A/V can give false positives, so I should never use it?
Updates can cause problems, so I shouldn't update?
Quite frankly all those positions are ridiculous.
If I get an email saying an IP tried to use Massscan or some Ddos script on my firewall, I goto ripe or lacnic or apnic or arin and it query the ip.
If this ip shows as a datacenter in St Petersburg Russia, or Shenzhen China, what are the chances it is not in St Petersburg or Shenzen? I would guess less than one in one thousand.
To the OP, instead of geo blocking you can use an IPS that can block on incoming and outbound traffic.
Rarely here someone will get their workstation on the IPS list because they go to a website that does something weird with a connection, or they click on a fakebook news story link.
Most often though the IPS list is full of people doing masscan or old apache/iis exploits, malformed email headers, illegal file attachments.