Lazyness
It hurts my insides that lazyness seems to always win over security.
Secure VPN from home? Sounds tough, we can just put all this stuff on a CD.
Encryption on the CD? Sounds time consuming, plus what happens if the user forgets their password? We can trust the VP of HR not to be an idiot right?
Sit down with all the VPs and try to tell them what can be counted as idiot behaviour with sensitive data? Nobody really likes to tell VPs what to do, and besides that, they rarely listen.
The whole chain is screwed. This sort of thing has to start from the top down, not from the IT department up, and it has to be backed with some serious penalties for breaking the rules.
I imagine it'll take a decade or two for that sort of thing to become popular...