You have to use PCI-DSS to store confidential information and tokenization for authentication if you want any real security. That costs money.
emails are a problem because of the way it's handled in bulk with subcontractors on the sender's end then on the receiver's end -- free-emails and all of the phishing (suckers).
|