This lively and timely talk will challenge almost every precept of orthodox information security, and shake up the conference theme "Trusting security". We will show how InfoSec practices are built on crumbling foundations, and that security itself is not intellectually secure. The recent tragic experience of data breaches -- at Target, Snapchat, Adobe Systems and RSA to name a very few -- shows that orthodox information security is simply not up to the task of securing valuable digital assets. We have to face facts: no amount of today's conventional security is ever going to protect assets worth billions of dollars. Our approach to InfoSec is based on old management process standards (which can be traced back to ISO 9000) and a ponderous technology neutrality that overly emphasises people and processes. The things we call "Information Security Management Systems" are not *systems* that any engineer would recognise but instead are flabby sets of documents and audit procedures. "Continuous security improvement" in reality is continuous document engorgement. Most ISMSs sit passively on shelves and share drives doing nothing for 12 months, until the next audit, when the papers become the centre of attention (not the actual security). Audit has become a sick joke. ISO 27000 and PCI assessors have the nerve to tell us their work only provides a snapshot, and if a breach occurs between visits, it's not their fault. In their words they admit therefore that audits do not predict performance between audits. The deep problem is that computer systems have become so very complex and so very fragile that they are not manageable by traditional means. Our standard security tools, including Threat & Risk Assessment and hierarchical layered network design, are rooted in conventional engineering. Failure Modes & Criticality Analysis works well in linear systems, where small perturbations have small effects, but IT is utterly unlike this. The smallest most trivial omission in software or in a server configuration can have dire unlimited consequences. Security needs to be re-thought from the bottom up. We need less rigid, less formulaic security management structures, that allow encourage people at the coal face to exercise their judgement and skill. We need straight talking CISOs with deep technical experience in how computers really work, and not 'suits' more focused on the C-suite than the dev teams. And we need to equate security with software quality and reliability, and demand that adequate time and resources be allowed for the detailed work to be done right. If we can't protect credit card numbers today, we need do things differently, standing as we are on the brink of the Internet of Things.