The reason that PI was not detected is because the attacker embedded a Flash object inside the Excel file. The Flash file was a 0day exploit that could download and execute a file, which in this case was the attacker's PI client.
From there, the game is up. Once inside the network, an attacker has a whole new set of doors to open. The simplest route, if the target is on an older operating system, is to dump the SAM file, which contains both local passwords as well as cached passwords. Cached passwords are nice because they are network logins, however 9 times out of 10 the local Administrator password is the same on all systems because system administrators frequently use the same local admin password when imaging lots of computers. Additionally, cached passwords are sometimes out of date due to password update policies. Local passwords are usually not subject to this, or if they are, it becomes irrelevant since a system administrator hasn't likely gone through and changed each local password.
Once you have a network password or local password, things get fun. There are 2 routes here. The attacker can go the frontend route, and attack the internal CRM that EMC has, or they can attack the development servers. Alternatively, they could just keep hacking each workstation, but that is unnecessary. Assuming we went the CRM route, we likely have or can easily obtain a valid login from our first target's computer. Once inside, unless there are solid permissions, we may have won. RSA likely had a record of each customer's purchase, which then had a record of each device and potentially some sort of key or code needed to predict the next token. I'll give RSA the benefit of being slightly smart, so those sort of keys probably won't be on the same CRM, or perhaps our login doesn't have access. Either way, we are in, and with some dissemination of materials available on other drives or within emails, the attacker could easily determine the location of the keys.
Once the attacker has whatever he needs, it's a quick trip to LinkedIn to find people that work at Lockheed Martin or whatever company you fancy. Then it's another spear phishing attack on that target to a page that looks like the target companies VPN. Grab the username, password, and PIN (also log the time) and you're good to go.
Now repeat the part where you enter the internal network and scour for information. Congratulations, you're now an Adaptive Persistent Threat. Pick your certificate up at the door.