Episode 45

full
Published on:

28th Jul 2026

Ep45: Fired for Failing a Phishing Test? What Binance Actually Does

Episode Summary:

Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme.

Key Topics Covered:

  • What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who fails
  • Can you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offense
  • How corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%)
  • "Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc lands
  • Accountability without a blame culture — four principles for getting Binance's seriousness without the fear
  • The boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patterns

Main Takeaways:

  • You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone owned
  • Punishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incident
  • The metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudly
  • Humans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the person
  • Fair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or report

Timestamps:

  • [0:00] The gotcha that shows up on your performance review
  • [1:03] What Binance's red team is actually doing
  • [2:23] Can you really get fired? Three strikes and the Krebs debate
  • [3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder
  • [5:03] "Weakest link"? The industry split, and where we land
  • [6:55] Accountability without a blame culture: four principles
  • [8:19] The boring middle thing that actually works

Tools & Resources Mentioned:

General education, not legal or HR advice. Reporting reflects coverage as of July 2026.

---

I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.

--

Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:

Listen to Byte Sized Security

--

Support this Podcast with a Tip:

Support Byte Sized Security

--

If you have questions for the show, feedback or topics you want covered. Please send a short email to [email protected] with the Subject line of "Byte-Sized Security" so I know it's about the podcast.

Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

Support Byte Sized Security

A huge thank you to our supporters, it means a lot that you support our podcast.

If you like the podcast and want to support it, too, you can leave us a tip using the button below. We really appreciate it and it only takes a moment!
Support Byte Sized Security
A
We haven’t had any Tips yet :( Maybe you could be the first!
Show artwork for Byte Sized Security

About the Podcast

Byte Sized Security
Snackable advice on cyber security best practices tailored for professionals on the go
In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go.

Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more.

Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out.

Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.
Support This Show

About your host

Profile picture for Marc David

Marc David

Marc David is a CISSP-certified Staff Security Engineer with 8+ years in dedicated security roles inside regulated healthcare, and the host of Byte-Sized Security. He describes his work in one line: "I get security tooling adopted by engineering teams who do not report to me." Most security programs fail at adoption, not at tool selection. Marc has driven API security monitoring, device trust, browser-based data loss prevention, and continuous mobile penetration testing to full coverage across engineering, IT, and platform groups where he holds no authority over anyone. His background spans HIPAA, HITRUST, and SOC 2 compliance, security automation, and awareness training built for people who never wanted training. Marc lives in the San Francisco Bay Area and speaks on security adoption, healthcare compliance, and automation.