It's a great counterpoint because with a large staff you can never solve the human element. It's also corollary to the hacking approaches we see regularly employed: Send an exploit payload via email to everyone in the company and somebody is bound to open it. In fact in the security space they've moved away from even saying you can protect the front door and are more focused on detection and correction once an intrusion occurs.