Episode 45

full
Published on:

28th Jul 2026

Ep45: Fired for Failing a Phishing Test? What Binance Actually Does

Episode Summary:

Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme.

Key Topics Covered:

  • What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who fails
  • Can you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offense
  • How corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%)
  • "Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc lands
  • Accountability without a blame culture — four principles for getting Binance's seriousness without the fear
  • The boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patterns

Main Takeaways:

  • You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone owned
  • Punishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incident
  • The metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudly
  • Humans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the person
  • Fair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or report

Timestamps:

  • [0:00] The gotcha that shows up on your performance review
  • [1:03] What Binance's red team is actually doing
  • [2:23] Can you really get fired? Three strikes and the Krebs debate
  • [3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder
  • [5:03] "Weakest link"? The industry split, and where we land
  • [6:55] Accountability without a blame culture: four principles
  • [8:19] The boring middle thing that actually works

Tools & Resources Mentioned:

General education, not legal or HR advice. Reporting reflects coverage as of July 2026.

---

I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

--

Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

Listen to Byte Sized Security

--

Support this Podcast with a Tip:

Support Byte Sized Security

--

If you have questions for the show, feedback or topics you want covered. Please send a short email to [email protected] with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

Support Byte Sized Security

A huge thank you to our supporters, it means a lot that you support our podcast.

If you like the podcast and want to support it, too, you can leave us a tip using the button below. We really appreciate it and it only takes a moment!
Support Byte Sized Security
A
We haven’t had any Tips yet :( Maybe you could be the first!
Show artwork for Byte Sized Security

About the Podcast

Byte Sized Security
Snackable advice on cyber security best practices tailored for professionals on the go
In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go.

Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more.

Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out.

Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.
Support This Show

About your host

Profile picture for Marc David

Marc David

Marc David is a Certified Information Systems Security Professional (CISSP) and the host of the cybersecurity podcast, Byte-Sized Security. He has over 15 years of experience in the information security field, specializing in network security, cloud security, and security awareness training. Marc is an engaging speaker and teacher with a passion for demystifying complex security topics. He got his start in security as a software developer for encrypted messaging platforms. Over his career, Marc has held security leadership roles at tech companies like Radius Networks and Vanco Payment Solutions. He now runs his own cybersecurity consulting and training firm helping businesses and individuals implement practical security controls. When he’s not hosting his popular security podcast, you can find Marc speaking at industry conferences or volunteering to teach kids cyber safety. Marc lives with his family outside of Boston where he also enjoys running, reading, and hiking.