You might also want to assess the "less fun" security aspects of the company.

As already previously stated, check out the companies security policies/standards/procedural documets etc...

I also think that the users security awareness plays a big part, and possibly the hardest to address. Look to see if users lock their PC's, put password on their monitors etc..