『Ep45: Fired for Failing a Phishing Test? What Binance Actually Does』のカバーアート

Ep45: Fired for Failing a Phishing Test? What Binance Actually Does

Ep45: Fired for Failing a Phishing Test? What Binance Actually Does

無料で聴く

ポッドキャストの詳細を見る
Episode Summary:Binance fires employees who repeatedly fail its monthly phishing tests — while the entire security-awareness industry insists you should never punish someone for clicking. In this episode Marc breaks down what Binance actually does, whether you can really get fired for failing a phishing test, how corporate phishing simulations work, and what a program looks like that takes security seriously without torching its own culture. The honest answer isn't at either extreme.Key Topics Covered:What Binance's red team is doing — monthly tests, recruiter and fake-conference lures, and mandatory remedial training for anyone who failsCan you really get fired? — the "three strikes" model and the 2019 Krebs on Security debate over whether a failed phish test should be a fireable offenseHow corporate phishing tests work — the baseline click rate, the "gotcha" landing page, and the Hoxhunt failure-rate ladder (no program 20–35% down to highly mature 2–5%)"Weakest link"? — the industry split between Hook Security's "never punish a click" and the accountability camp, and where Marc landsAccountability without a blame culture — four principles for getting Binance's seriousness without the fearThe boring middle thing that actually works — train relentlessly, test fairly, measure reporting, and save real consequences for real patternsMain Takeaways:You usually can't get fired for a single click — real programs reserve consequences for repeated failures in high-risk roles, not one slip-up someone ownedPunishing clicks backfires: people who fear consequences hide mistakes, and a hidden compromise turns a five-minute cleanup into a five-month incidentThe metric that predicts resilience is report rate, not click rate — reward the people who spot the phish and hit "report," loudlyHumans aren't the weakest link; untrained, unsupported humans are — most failure is the program, not the personFair escalation targets the overlap of three things: repeated failure, high-risk access, and refusing to train or reportTimestamps:[0:00] The gotcha that shows up on your performance review[1:03] What Binance's red team is actually doing[2:23] Can you really get fired? Three strikes and the Krebs debate[3:34] How corporate phishing tests work, and the Hoxhunt failure-rate ladder[5:03] "Weakest link"? The industry split, and where we land[6:55] Accountability without a blame culture: four principles[8:19] The boring middle thing that actually worksTools & Resources Mentioned:Binance runs monthly phishing tests (crypto.news)Repeated failures may lead to dismissal (WEEX)Addressing the repeat phishing offender (IT Brew)"Should Failing Phish Tests Be a Fireable Offense?" (Krebs on Security, 2019)What to do (and not do) when employees click (Hook Security)What's a good phishing failure rate? (Hoxhunt benchmarks)KnowBe4 phishing security testProofpoint phishing simulationMicrosoft Defender attack simulation trainingFull written article: Fired for failing a phishing test?Why modern phishing beats smart peopleWhy employee security awareness training mattersGeneral education, not legal or HR advice. Reporting reflects coverage as of July 2026.---I do hope you enjoyed this episode of the podcast. Here are some helpful resources including any sites that were mentioned in this episode.--Find subscriber links on my site, add to your podcast player, or listen on the web players on my site:Listen to Byte Sized Security --Support this Podcast with a Tip:Support Byte Sized Security --If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast.Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません