Well, yes, those don't have the card details or direct access to them, but they are legitimate ways into a company system. It doesn't matter how a miscreant gets in, but once they are inside, most bets are off. Internal security is usually much lower priority than external security.

