Take a step back from the problem. If you have a well documented policy that no one is following, think about why that is. Maybe the policy is just too much of a pain in the ass for people to comply with and still get their jobs done. Maybe you need a different policy.
Anyone can sit around and complain about how stupid or noncompliant their users are. But seeing problems from the prospective of the user (or boss) is the difference between a good IT person and a great one.
In the case of backup, consider continuous protection solutions like mozy.com.
This is a an extremely one-sided presentation of this story. Linus makes some controversial but insightful points about the security obsessed culture in the community. This should not have been a "Linus has gone mad" story. This is a legitimate re-evaluation of how security patches are handled.
Read the thread, make your own decision:
http://thread.gmane.org/gmane.linux.kernel/701694/focus=706950
Don't compare floating point numbers solely for equality.