You are saying we can forget the high-grade security risks because there are plenty of incompetent people around ?

On page 3 of this you can find why this is a very weak argument. The weapons-grade actors will use exactly such weaknesses to flatten entire corporations, complete with dedicated, full time IT security staff.

MTAs, Email programs, EDI systems, web servers, TCP/IP stacks - they are exposed to ALL bad guys of the planet. As soon as they have a foot inside your intranet, all the funny service ports of your PCs (of services mostly running inside the kernel) will be exposed too. And all the half baked database listener processes.

