To start, I admit I've done access control in the past that I now know wasn't great (and am glad that those installs don't get connected to the Internet).
Nowadays, I'd quite like (it isn't necessary, but would be nice) to access some of my LAN boxes from the Internet - and I've got loads of material saying how to set it all up, thanks, but don't trust it enough to take the risk (for the perceived gains).
> You need to address expertise
Gaining expertise, particularly as an autodidact[1], in online security seems strangely hard, compared to pretty much any other area of ops (for a small LAN) and/or programming.
First is a lack of confidence in proving that the methods being proposed actually work, and against what: basically, you have to be able to demonstrate that you can break into the "unprotected but otherwise correctly set up and working system" first, then show that the added protection fixes the issue. I.e. turn a claim (or even just a vague worry) about a security issue into a testable issue in the bug tracker. To do that, I first need to be able to break into the online system like a real Bad Guy and for some reason the books[2] on securing your Apache server has recipes for setting permissions but none for smashing down the door in the first place!
Second, to be blunt, is a dismissive tone about the subject in forums where you'd hope to see better. Even in Register forums, there tends to be many replies that basically boil down to "well, I do better than that"[3] and no pointers to practical sources of learning. Compare that to other subjects (h/w and s/w) where you can often get useable tips and tricks.
To be frank, the end result is that I have very little confidence in any of the "how to do online securely" claims :-(
[1] I'm not in a position to just be put onto an expensive course at company expense
[2] tutorials etc; unless you have some references to better materials.
[3] comments on a Reg story last week (URL) even had someone else pointing out this attitude