Artwork for podcast Byte Sized Security
Ep45: Fired for Failing a Phishing Test? What Binance Actually Does
Episode 4528th July 2026 • Byte Sized Security • Marc David
00:00:00 00:10:44

Share Episode

Shownotes

Episode Summary:

Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme.

Key Topics Covered:

  • What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who fails
  • Can you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offense
  • How corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%)
  • "Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc lands
  • Accountability without a blame culture — four principles for getting Binance's seriousness without the fear
  • The boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patterns

Main Takeaways:

  • You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone owned
  • Punishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incident
  • The metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudly
  • Humans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the person
  • Fair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or report

Timestamps:

  • [0:00] The gotcha that shows up on your performance review
  • [1:03] What Binance's red team is actually doing
  • [2:23] Can you really get fired? Three strikes and the Krebs debate
  • [3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder
  • [5:03] "Weakest link"? The industry split, and where we land
  • [6:55] Accountability without a blame culture: four principles
  • [8:19] The boring middle thing that actually works

Tools & Resources Mentioned:

General education, not legal or HR advice. Reporting reflects coverage as of July 2026.

---

I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

--

Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

Listen to Byte Sized Security

--

Support this Podcast with a Tip:

Support Byte Sized Security

--

If you have questions for the show, feedback or topics you want covered. Please send a short email to [email protected] with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

Links

Chapters

Video

More from YouTube