Snort is a good selection and serves its purpose very well. Many snort signatures are posted less than a day after a major worm comes out (ex sasser). However, the ease of use might be something to watch here. Its not the easiest thing to setup and use.

There are also other issues to look at. If you are trying to protect your data, an intrusion detection system is only one component of security. Remember, an IDS is mainly for detecting intrusions. Protecting your data involves many more applications and solutions.

A firewall is one of the most basic but one of the best defenses you can have, from both internal (LAN) and external (internet) intruders.

Patching your systems and keeping them up to date is another basic, low cost, but critical function of security.

Another thing to look at is the applications and actual network structure your running.

There are many factors to security, and an intrusion detection system is not the only solution, however it is good.