I presume the argument some middle management type makes is that exposing their security protocols makes it trivial for a fraudster to work around. Obviously this is a fallacy because any genuine fraudsters has the incentive to work this all out by trial and error, if the information isn't freely available to them on some dark corner of the internet.