I’d switch firms immediately if that’s their level of opsec awareness
I spent 3 months on secure document transfer portal system, got scrapped after 4 months because clients wanted their forms as Word/PDF and they wanted them without hopping through any hoops.
Email is not an end-to-end secure data protocol without the use of client side encryption/decryption like PGP/GPG, but even then, sender/receiver and time are all in the envelop metadata.
No matter what format you hand a recipient a document in, they can always make a photocopy and pass it on.
And this is still irrelevant to sending email to the wrong recipient, so I don’t know why you’re stuck on infra security.
if you attach documents 'inside' the mail (i.e. MIME encoded multipart) that is most definitely not secure.
1) you do not know how that mail gets delivered, not necessarily via servers that support encryption 2) you do not know how that mail, or the attachment, gets stored on the local machine 3) you do now know if the mail, or attachment, is sent to someone else 4) you cannot revoke the access to the document once the Need To Known stops
In our ISMS, sending Highly Sensitive data (ex: customer data) by attaching directly to a mail, is strictly not allowed by the IT charter. We explain it during an on-boarding meeting to all new staff members. And it's a fireable offense.
Worst was at another company where a person with the same name has just left, so they gave me that email address. Turned out he was subscribed to several Confluence pages for which I now received updates. But I didn't get his Confluence account, so I couldn't unsubscribe from those updates.
It's unusable. I have received full blown mortgage applications from couples in Mexico (including paystubs, tax forms, credit ratings, phone bills, passports). Mostly, these days, it's transaction notifications for a guy in Nigeria and phone bills for people in South America.
Neither of our names can be confused with a last name and yet I had multiple people writing to it incorrectly, including: as the email attached to a Diners credit card (I called Diners and they asked me what's the right one and "if I don't know the right one how do I know that it's wrong"), as the email for a school 400 km from home (another family must have had the same idea), once for some lawyer stuff (I then learnt that about 100 people in Italy do have my wife's name as a very uncommon last name), and lately as the recovery email for another Google account.
Still annoying, but not as bad as gmail. I just got an email, in Italian, about someone adding a passkey to their ebay account. No way to tell ebay it's not their address / it's not my account.
Edit: side note, your username is also the name of my favorite fusball table maker.
At the risk of nitpicking, @gmail.com email addresses use a dots don't matter policy [0] so really you have a common firstnamelastname@gmail.com and are free to add dots wherever you like.