We dont have an IT specialist and never will, we are too small.
Our database and systems were written long before people fussed about encryption as such there is no facility to do this, taking it offsite is no different to breaking into the office and accessing the systems, we comply where we are required to by the ICO however even when shredding customers details there are no rules on what level of security we are required to use, it simply has to be "adequate" which is wholly subjective.
Nothing has gone wrong in 18 years so i dont expect it to now, we bank hundreds of credit cards a day and dont have a single CVV number either.....why, because the bank doesnt require them - we have NEVER had a single card fraud through our systems!
That said policies are being reviewd with IT to bring it up to date so i shall look at how it is done and see how we can improve it and make it safer for all.