In this talk, Michael Belton discusses his past experiences delivering penetration testing services. The format for this talk is conversational and audience participation is encouraged. Michael will provide background on the situation, discuss the actual techniques and attacks used in the hack and use that to identify defense-in-depth measures that could have mitigated risk. This talk is intended to learn from the mistakes of the past.