Probably the best way to describe this, is to compare security and pro sports teams. From what I have read, the NSA is a top tear team winning championships across the globe, with billions in research and development, and thousands of highly trained athletes, living and breathing this day in and day out. Yet, they are matched up against a local beer league who likes to play casually Thursday nights. Who do you think is going to win?
Go read the "A Look at Targeted Attacks Through the Lense of an NGO" [3] paper, then put yourself in their shoes. Think about the IT resources a small NGO with 30-50 employees has. Maybe they have a sysadmin and a helpdesk guy. They are dead meat. The threats are so vast, spear phishing, target malware via MITM attacks, etc. It almost seems hopeless. But it is not just the NSA at the top of the heap, you have lots of foreign governments, which have direct access to your playing field via the internet.
Think about the resources that Google, Facebook, and Apple throw at security, then you see something like Operation Aurora [4, 5]. What chance does an ISP or small business have? None. Personally, it just seems like the entire model is broken. Yet, nothing seems to change, in that we are all just waiting for the next zero day to drop, and the cycle continues. All it takes is one targeted zero day addressed to a normal employee, the attackers gain access to the network, then move laterally [6, 7]. The odds are further stacked, in that you have a top tear team against a targeted employee, who doesn't even know the game.
ps. sorry for the tone of this
[1] https://firstlook.org/theintercept/2014/03/20/inside-nsa-sec...
[2] http://www.theguardian.com/world/2014/aug/13/snowden-nsa-syr...
[3] http://www.mpi-sws.org/~stevens/pubs/sec14.pdf
[4] http://www.wired.com/2010/01/google-hack-attack/
[5] http://en.wikipedia.org/wiki/Operation_Aurora
[6] http://g0s.org/wp-content/uploads/2013/downloads/Inside_Repo...
[7] http://intelreport.mandiant.com/Mandiant_APT1_Report.pdf