The main problem is that if people really want to get round whatever security measures you've put in place - they will. People have far more knowledge about various systems now than they did just a couple of years ago, need to email a report but it wont let you upload a file from an external source?
Someone in the office will always know how to get round it. Sure you could order a batch of shiny new base units with no USB ports. But they'll still have an internet connection, so you're pretty much back to square one.
Before any internal data theft occurs; someone somewhere believes they can do it. That's what companies need to work on - eliminating that thought. Once people believe they can; they'll most certainly try.