Using a portable device with "sensitive information" is a bit of a joke, frankly. Unless you can use device encryption. Applies both to laptop and particularly PDA. Yes you can force strong authentication for PDAs and even encrypt them - at a cost. You should investigate whole-disk or folder encryption for a laptop if the information will reside on it.
The only secure method to access data over the internet is via a VPN - either SSL or IPSec based. Of course you can use an unencrypted link if the data itself is encrypted - e.g. using PGP for email.
SD