If you listen to the media or security vendors, every organisation is being compromised by bespoke "Mad Zero Day" hacks from China and you puny humans have no way of defeating them. In this talk I'll go through a number of methods that are actually used in real life, based on our own red team engagements, as well as breach information from other organisations in similar industries. I'll explain how and why these things were found, what decisions were made and how best to prevent this. No security or incident response experience is required for this talk. The topics will all be relevant to and based on operations and development, but with an eye to security.