Tip of the iceberg...
Mind you, most government organisations are reasonably good because of a multi-tier approach to security and documented policies. However, I did work for one organisation who reacted well with measures against the Blaster worm, but decided to ignore the Slammer worm threat even though they were vulnerable!