this is not an advantage then, you don't need to be a seasoned architect to see all kinds of potential issues with publicly exposing these APIs, even with proper security. I mean this is the core of every bank, not some application X storing some small subsets of crucial data.
Best and easiest security to achieve and maintain is no public access at all (something like physically separated networks vs authenticated ones)