I break down real breaches before post-mortems get sanitised and call out the security theatre that wastes money. For the CIO who approved the budget, the CISO who signed off the vendor, and the CFO asking why it cost this much and still failed.