In the big large world of large and private companies and whatnot, you don't deal with 'we want 100% secure unhackable encryption and programs', you deal with % certainty that the information you've got is legitimate and % of it which is true, and % change it's been read by someone else.
Nothing is 100%, not even military can get 100%!
So don't worry if you can't get near 100%
There's loads of factors that can influence them, if you're using signed PKI certificates, a hacker doesn't have to nick your certificates to be able to read or send false data, they can extract them server the server that signed them, for instance, they could forensically extract them from a USB/PC/Hard drive you've chucked.
As mad as it may seem, your system being not 100% secure is fine








