I read a while back about a security firm that was hired to "tiger team" a big multinational company that was very proud of their security. They'd decided to get everything tested to be able to brag about how secure everything was. Lots of cameras, keypad combinations, guards, motion sensors, everything password-protected.
The tiger team went out and bought a few dozen cheap little USB flash drives, loaded them up with trojans and cracking tools, and then 'lost' them outside the company's staff entrances over the next few days.
They never even had to get physically past the front door, they got completely into the company's security -- thanks to all the employees who thought, "Oh, look, somebody dropped a flash drive. Lucky me!" and took it in with them and plugged it into their office machine before getting their coffee.