Precisely. The point is, the server we currently host our mail has a plesk license because it is also a webserver/mailserver for our smaller legacy clients, it has a DrWeb AV license, and a 4PSA anti-spam license.
Our corporate email gives the server a hammering, so why not free the recourses off to the client and use something with better interface for webmail than squirrelmail or horde/imp.
Exactley. If you are worried about insecure email, don't send email. There is nothing to stop somebody who wants to, from intercepting mails or even sniffing plain text pop3 passwords straight off the wire should they wish. If you are sending something sensitive, send it attached, and encrypt it. At least then, if it does fall into the wrong hands, they can't do anything with it.