Any application you access via web browser is insecure.
Most companies in regulated industries with high value data and information approach security from a liability standpoint. They know their applications are at risk and insecure. If they take appropriate precautions they won't make their systems secure but they WILL prevent criminal charges against them when they have a breach. They'll be subject to civil suits, but not criminal.
Your claim is false. The iPhone is secure and the data received or sent is encrypted to a 256 bit AES standard that requires 5.62 undecillion years to go through all possible passcodes with only 16 characters entangled with the UUID of the device.
The Hacker Team, the company that sells the tools to break into mobile devices to the NSA, FBI, other police agencies around the world, admits they have tools that can break into every mobile OS except un-jailbroken Apple iOS. They have hit it and bounced every time. To put it bluntly, they have not succeeded in breaking into iPhones or iPads. . . and have nothing to sell for that platform to these agencies.