When I took over the department the first thing I did was start looking at security - they had a no-policy policy in place before I joined. The idea was that anyone could access anything on the Net at any time.
They had suspected they had productivity problems, had problems with viruses and compromised machines, had issues with groups of people emailing jokes and explicit pictures back and forth, etc... You know, a generally uncontrolled environment with immature people.
When I got there I installed a new firewall in drop-in mode so that no one was any wiser, monitoring all traffic and seeing exactly how bad the issue was.
After 30 days we implemented a new security model and put an end to all of the BS and playing. Funny thing was that the worst abusers were also the lest productive in all areas. Once we took away access to sites that didn't meet our business needs, productivity increase almost 130% that first month....
It's amazing what people will do when they think they are owed access and when they think no-one is watching.