The gist is that he, knowing absolutely nothing about security, could figure out the exploit.
His finance audience doesn't want to know the details of the security problems, nor do they need to. However, it's valuable for them to realize how this information is just sitting around on a company DB for anyone who can Google "SQL injection" to steal.
His finance audience doesn't want to know the details of the security problems, nor do they need to. However, it's valuable for them to realize how this information is just sitting around on a company DB for anyone who can Google "SQL injection" to steal.