That's shocking. I know people are dopey, but 50%? I'd have guessed 20% at most.
Time and time again the technology industry has failed to consider security as a serious issue, never mind develop systems that are robust and transparent.
We don't have botnets, booby-trapped mail attachments, script-hackable servers, USB drives that can carry a viral payload, and all the rest because users are stupid, but because the industry's default culture is to think of security as an esoteric side issue, and not a non-negotiable critical feature in all IT systems.
Thing #1 to remember if you're in infosec is that you must pitch it based on the money saved by not having expensive problems like having to hire outside consultants and auditors after a breach.