Agreed, Krogh.
Authentication you can handle on the ColdFusion side, with a user/password database, but for securing the data transmitted, there's no substitute for HTTPS/SSL that has a better combination of ease of implementation/use and strength. It's certainly not perfect, but most clients will accept it once you tell them that this is the strength that major banks use for their own online financial transactions.