Implicit in this comment is the assumption that current technology is pretty much the best we can do?
> IT departments will never have enough money/time/staff to keep systems up to date with the latest OS (look at the number of people still running critical systems on Windows XP).
Why is it that even slightly old systems are so buggy that they are trivially hackable for a moderately well funded group?
Modern security is based primarily on security through obscurity. As long as you stay up to date, all of the bugs you have are sufficiently obscure that knowledge about them is probably too expensive for the type of hacker that would target you.
> Users will always open attachments from people they don't know, click links, or even pick up random USB sticks.
Why is any of that a problem? A user should not be able to threaten an organization's IT system even if they were outright hostile (unless they were put in a specific position of trust within IT; but even then the amount of damage they should be able to do from their personal work computer should be limited).