A compromised employee machine will always cause problems. (Just look at Google, the New York Times, etc.) We're obviously careful about what goes in email, and I think the open-by-default policy largely makes the security properties of email clearer. (I.e., don't put sensitive material here.)