I went to a security con a couple of years ago where one speaker pointed out that security recommendations come so thick and fast, that not even security professionals bother following many of them - and these are the people who both understand the issues and are motivated by them.
Yes, that's another problem: patching holes with chewing gum instead of systematic improvements. The latter involves abstract reasoning, something that seems somehow lacking in infosec.