This is a month or so old, but good reading. PWC research on global state of information security.
Net: High-level: Strategic priorities for the next year: 10 most common answers.
Disaster recovery/business continuityEmployee awareness programs Data backupOverall information security strategyNetwork firewallsCentralized security information management systemPeriodic security audits Monitoring employeesMonitoring security reports (log files, vulnerability reports and so on)Spending on intellectual property protectionhttp://www.cio.com/archive/091505/global.html