Running a WSUS update server on your network is no guarantee that updates will be pushed out. Network and server personnel need to review the reports on the server and patch any holes on systems that have failed to get their updates. Automatic security doesn't mean that all computers will be up to date and patched. An audit of all computers should be performed on a regular basis. Any system that fails to get updates should be patched immediately.
We often take passwords for granted. As we develop relationships with employees, the simple trust that we gain from these relationships should not apply to passwords. Passwords are critical to the survival of your data. You should develop a system of identifying personnel who call to have their passwords changed. Never respond to an email request and don't give out passwords to unauthorized personnel.
A firewall is put in place to protect your network. If you fail to keep the firewall up to date with software, firmware and rules, you will create a security hole. Firewalls are one of the first lines of defense against any type of network breach. The dangers of not monitoring your firewall logs cannot be overemphasized.
Never use unencrypted protocols on you network to manage other devices. Simple scanning software can pick up plain text data and your passwords or data may be captured.
With viruses and malware changing everyday, you cannot place a computer on your network until is protected. Updates for antimalware and antivirus should be controlled at an enterprise level. These updates should be randomly checked to make sure your computers are protected.
Computers should be checked for unnecessary services such as telnetd or ftpd. Any service that can jeopardize your network should be stopped or removed from computers or disabled on any device that is on your network.
While these security issues are critical, training your personnel to look for these and any security issue such as computers not on a domain, simple file sharing, and temporary security fixes, failing to encrypt and protect data, failing to patch all software on computers and other common security issues are important issues to look for.