Apathy
The biggest thing I encountered was an absolute apathy towards security. The council's head of IT really couldn't give a damn about the fact they had no IDS or IPS, even though the CESG guidelines for the PSN CoCo said that they should have one.
They didn't seem in the slightest bit concerned that not having tools such as this meant that it in all likelihood they had been hacked already, and we had no way of knowing.
As well as educating the users, the focus needs to be on educating the people in charge - the Data Protection Officer and the Head of IT positions were often trophy positions on the way to other roles in the council, so their input and strategic direction were more down to making themselves look good, rather than making the right decisions for the organisation.