Binance runs an internal security system that carries out simulated phishing attacks on employees every month and can dismiss staff who repeatedly fail.
Cointelegraph reported on Saturday that Binance Chief Security Officer Jimmy Su (지미 수) said the test results are also reflected in employee performance evaluations.
The simulated attacks are handled by Binance’s internal ethical hacking group, the red team. The red team infiltrates systems to find vulnerabilities and also designs fake attack scenarios targeting employees. Binance conducts the tests each month to check whether security levels are improving and provides remedial training to employees who fail.
Binance has operated the simulated attacks for 3 to 4 years. The red team approaches staff while posing as recruiters or uses invitations to free conferences as bait to check whether they provide personal information. The results are reflected in performance evaluations to encourage employees to pass the tests. Cointelegraph reported that repeated and serious failures can push evaluations to the lowest tier and lead to dismissal.