Earlier quoted context omitted.
Citation needed! Not just being pedantic here for the sake of it, I think it would be good to know how much safer experts generally are. Just saying "we're better than them!" isn't very convincing or useful.
I'm skeptical too. "The experts", e.g. HBGary, get pwned worse than having a bunch of crapware on their desktop, but it's for the same types of mistakes: "So what do we have in total? A Web application with SQL injection flaws and insecure passwords. Passwords that were badly chosen. Passwords that were reused. Servers that allowed password-based authentication. Systems that weren't patched. And an astonishing willin…
Where I work the actual IT staff/server admins are pretty safe. They update, patch, and in general choose good passwords.
The programmers... ugh, good lord. They have the worst practices ever.