NatWest are particularly terrible. Last time I checked, in-branch they were still using Internet Explorer to visit an http (not https) site on their intranet to launch via Java Web Start a thin client to log in to their (I assume) mainframe to actually do things.
There's a number of places in that chain of events that something could go nastily wrong, despite them owning every part of that chain.