I have talked to less than 10 organizations that have good - focused, security teams.
I have talked to less than 2 banks that focus on security, and do it well.
Most of the IT Security people at organizations you actually do business with, have IT Security titles but are project managers.
I cannot unlearn how poorly security is treated, even after the Sony breach hit the market.
If you bank, use credit cards for anything, use any social networking, you will be losing your PII, I promise.
PII has about 15x the value of a single credit card number now, it isn't about credit cards anymore.
On the flip side, exploits are easier. BackTrack anyone?