Earlier quoted context omitted.
Law firms that send very sensitive legal documents over email… #sigh I’d switch firms immediately if that’s their level of opsec awareness
What are you talking about? If you send emails from eg GMail to Gmail, it's fairly secure.
if you attach documents 'inside' the mail (i.e. MIME encoded multipart) that is most definitely not secure.
1) you do not know how that mail gets delivered, not necessarily via servers that support encryption 2) you do not know how that mail, or the attachment, gets stored on the local machine 3) you do now know if the mail, or attachment, is sent to someone else 4) you cannot revoke the access to the document once the Need To Known stops
In our ISMS, sending Highly Sensitive data (ex: customer data) by attaching directly to a mail, is strictly not allowed by the IT charter. We explain it during an on-boarding meeting to all new staff members. And it's a fireable offense.