IT Analyst firm 451 Research (these guys are very good by the way, check them out) asked over 200 InfoSec professionals what their top information security pain points were. The answers are very interesting. I'm only taking the Top 10, the list went on to 30, but the percentages fell below 8% so I skipped them.
Here is the list:
1. Mobile Device Security - 16%
2. User Behavior - 11%
3. Vulnerability Management - 9%
4. Security Awareness Training - 9%
5. Hackers - 9%
6. Third-party Security - 9%
7. Resource Constraints - 9%
8. Monitoring - 8%
9. Data Leakage Prevention - 8%
10. Compliance/Auditing - 8%
We are of course happy to mention that with effective security awareness training, you can actually DO something about the User Behavior headache (a large part caused by social engineering), and cover two out of your Top 5 problems! Check out the new 2015 version of Kevin Mitnick Security Awareness Training