Binance Targets Staff Security Awareness with Monthly Phishing Tests
Binance's internal red team conducts monthly phishing tests on employees to assess their security awareness. The simulated attacks mimic real threats, including fake job recruiter outreach and free conference invitations.
The goal is to identify vulnerabilities in staff behavior before outside attackers exploit them. Employees who fail the test must complete remedial training, and repeated failures can negatively impact their performance ratings.
Binance has run the phishing program for three to four years, and Chief Security Officer Jimmy Su says it has improved staff security habits over time. The exchange treats consistent failure as a genuine security risk rather than a minor lapse.