In Vegas this year (July 2010) there was an interesting contest going on, it was a social engineering capture the flag setup by the great guys at www.social-engineer.org.
This was a great event, and it has attracted some media coverage. The contest and the stories in the press demonstrate the fact issues do exist, its a real problem, not something made up by people in the business in attempt to generate work. The contest was run in an ethical and legal manner, but if with these constraints its clear people are willing to give out alot of information, and still need to be educated.
Companies and individuals can learn alot from these contests and their findings. I encourage businesses and people in the appropriate roles to start properly educating about these real risks, and provide the patches for human stupidity. This needs to be a living, evolving process, not a once a year check list.