Here's another free webcast from Rapid7, home of Metasploit and Nexpose, that I thought might be a great help when securing your own environment as well as talking to the higher ups. Good luck with that one.

In the current threat environment, the chances of getting breached are pretty high. What are the steps you’ve taken to reduce that risk? In the event it does happen, what actions will you take to act quickly?
Join Marcus Carey, Security Researcher at Rapid7, for a free webcast, "Life's a Breach! Lessons learned from recent high profile breaches," on
Thursday, June 14 at 2:00 pm EDT. The webcast will discuss what we can learn from recent high profile breaches, including LinkedIn and Global Payments.
Marcus will identify:
• Attacker profiles and their modus operandi
• Common security miscues
• Cryptography and cryptanalysis best practices
• Incident response and business continuity best practices
Attendees of this webcast will gain practical advice on best practice approaches to minimizing the risk and potential business impact of a breach.
Reserve your spot now - space is limited
http://information.rapid7.com/Webcast-lessonslearned-breaches-registration.html?LS=1152784&CS=ehEnjoy,
Don