Ep45: Fired for Failing a Phishing Test? What Binance Actually Does
Episode Summary:
Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme.
Key Topics Covered:
- What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who fails
- Can you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offense
- How corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%)
- "Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc lands
- Accountability without a blame culture — four principles for getting Binance's seriousness without the fear
- The boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patterns
Main Takeaways:
- You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone owned
- Punishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incident
- The metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudly
- Humans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the person
- Fair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or report
Timestamps:
- [0:00] The gotcha that shows up on your performance review
- [1:03] What Binance's red team is actually doing
- [2:23] Can you really get fired? Three strikes and the Krebs debate
- [3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder
- [5:03] "Weakest link"? The industry split, and where we land
- [6:55] Accountability without a blame culture: four principles
- [8:19] The boring middle thing that actually works
Tools & Resources Mentioned:
- Binance runs monthly phishing tests (crypto.news)
- Repeated failures may lead to dismissal (WEEX)
- Addressing the repeat phishing offender (IT Brew)
- "Should Failing Phish Tests Be a Fireable Offense?" (Krebs on Security, 2019)
- What to do (and not do) when employees click (Hook Security)
- What's a good phishing failure rate? (Hoxhunt benchmarks)
- KnowBe4 phishing security test
- Proofpoint phishing simulation
- Microsoft Defender attack simulation training
- Full written article: Fired for failing a phishing test?
- Why modern phishing beats smart people
- Why employee security awareness training matters
General education, not legal or HR advice. Reporting reflects coverage as of July 2026.
---
I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.
--
Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:
--
Support this Podcast with a Tip:
--
If you have questions for the show, feedback or topics you want covered. Please send a short email to [email protected] with the Subject line of "Byte-Sized Security" so I know it's about the podcast.
Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
