I don't have any statistics, but my opinion is that security has to be addressed from every angle, and that if anything falls through the cracks, whether it's in the firewall, the server, application or database, it could put the whole enterprise at risk. Also, security isn't a one-time consideration. It needs to be monitored, evaluated and improved upon all the time. Hackers are doing the same, working non-stop at getting through all the known security measures. We need to be vigilent about keeping security measures up-to-date and effective for current situations.

That's my two cents.