For card system master keys, you don't use open source tools, you buy a set of properly hardened hardware modules, and follow the appropriate (documented, tested, verified) 'rituals' on them. IIRC the set we used cost something in the ballpark of $50k-$100k, which is not really much compared to all the other things that are table stakes of doing it properly. You can do it much cheaper if the risks are lower and you need less tamper resistance and auditing because you're less likely to have (for example) one of the trusted authorised employees be malicious and willing to invest nontrivial effort in circumventing the system.
Because losing these keys can be very, very, very expensive.
For an example (somewhat similar to this Postbank case) see India Cosmos Bank 2018 incident (https://www.reuters.com/article/cyber-heist-india-idUSL4N1V5... is one link) where criminals generated fake cards to cash out some $13 million; and replacing 12M bank cards also has an huge cost to replace the cards (perhaps roughly $12M - $1 per card replacement is plausible though possibly on the cheap side) even if we ignore the reputation cost.