A phishing programme should get harder as people get better at recognising it. Starting with an obvious fake password reset and jumping straight to a convincing supplier message does not measure improvement; it measures whether the first test was fair. A platform with tiered phishing difficulty lets a security team build skill progressively, target support where it is needed and keep later simulations relevant without harvesting credentials.
The best platform is not the one with the most difficult templates. It is the one that makes difficulty explainable, lets an administrator choose the next step and turns every result into coaching.
Key takeaways
- Use at least three difficulty levels, from obvious red flags to realistic business-context requests.
- Change one variable at a time so a click or report can be explained and acted on.
- Pair every failed simulation with immediate education and a follow-up course.
- Track reports as well as clicks; reporting is a safe behaviour, not a failed result.
- Choose a platform that protects learners, avoids credential harvesting and produces client-ready evidence.
What tiered phishing difficulty means
Tiered difficulty is a deliberate progression in the signals presented to a learner. An easy simulation may contain several clues: a strange sender, poor grammar, an urgent demand and an unfamiliar link. A harder message may use a familiar service, a plausible request and a well-written subject line, leaving the recipient to verify the action rather than simply spot an error.
Difficulty should describe the decision, not the person. A low score does not mean someone is careless, and a high score does not make someone immune to a new tactic. The purpose of the tiers is to provide a safe practice ladder. Start with recognition, build verification habits, then test whether the habit survives pressure and context.
A useful platform exposes why a template sits at a particular level. The indicators might include urgency, sender familiarity, request sensitivity, link destination, attachment type and how much internal context the message uses. Without that explanation, an administrator cannot tell whether a campaign became harder because the scenario improved or because the template was simply less transparent.
The four levels a buying team should test
Level one: obvious signals
The first level is for new learners, new starters and teams that have never practised together. Use a familiar scenario with visible warning signs: a mismatched sender, an unexpected attachment, a request for a password or an urgent instruction to bypass normal process. The landing page should explain the clues without blame.
The outcome to watch is not only whether someone clicked. It is whether they can name the safe action: pause, avoid the link, use a trusted route to verify and report the message.
Level two: believable routine
The second level should resemble a normal workday. Examples include an invoice awaiting approval, a shared document, a delivery update or a request to review a customer record. Remove one obvious clue but keep a verification point. Finance staff may need to check a payment request; a customer team may need to confirm a booking change.
Assign this level after the baseline course or a successful first campaign. The point is to test whether people apply the rule to a familiar workflow rather than whether they memorise a list of red flags.
Level three: familiar service and internal context
A stronger simulation uses a service, team name or process that the organisation genuinely uses. The request may look like a Microsoft 365 sign-in alert, a cloud-file share, a payroll message or an internal notice. It should still be safe and clearly separated from a real credential page.
This level needs careful targeting. Do not send an executive impersonation scenario to a group that cannot approve the action, and do not use a payroll scenario with people who never see payroll messages. Relevance improves the quality of the lesson, but it also increases the responsibility to keep the exercise controlled.
Level four: hard to detect
The final level tests verification under pressure. The message can be well written, timed around a real business event and addressed to a role that handles the request. The safe response is not to identify a spelling mistake; it is to confirm the instruction through a known contact, a normal system or an independent approval path.
Hard simulations should be earned, not used as a first impression. If the earlier tiers show that a group does not know how to report or verify, increasing difficulty adds noise and frustration. Give the group a short practice cycle, then retest the same behaviour with a new scenario.
Six platform capabilities that matter
1. A visible difficulty model
Ask to see how the platform labels and explains difficulty. The label can be simple, but the administrator should know which signals are present and what makes the next level different. A catalogue that says easy or hard without a reason is difficult to govern.
2. Flexible targeting
The platform should target by role, team, location, client and campaign history. It should support separate groups for finance, executives, contractors and new starters without forcing an administrator to build every campaign from scratch.
3. Automatic remediation
A click should create a learning moment while the decision is fresh. Cyber Aware describes a workflow where a learner who clicks sees a branded explainer and is automatically enrolled in a failed-phishing course. That is more useful than waiting for a monthly spreadsheet. The phishing programme explains the click, report and coaching workflow.
4. Positive reinforcement
People who do not click should not disappear from the programme. A congratulations message that shows the simulated email and reinforces the safe behaviour can make reporting and verification feel normal. Recognition is especially useful when the organisation wants more reports, not only fewer clicks.
5. Safe data handling
A phishing test should not collect real passwords. The administrator needs campaign outcomes, not a credential database. Confirm how the platform handles landing pages, links, personal data, exclusions, test addresses and retention before launching a realistic campaign.
6. Decision-ready reporting
The report should separate sent, opened, clicked, reported, completed and overdue. It should show the campaign level, role and date so a manager can decide whether to coach, repeat or move the group up a tier. Cyber Aware's Human Risk Reporting page describes combining phishing behaviour with overdue courses and failed quizzes in a Human Risk Score. That combined view is more useful than a click rate on its own.
How the main platform approaches differ
A native email-security suite can be convenient when the team already administers that environment. A specialist awareness platform can offer a wider content library, more structured remediation and client-ready reporting. A managed provider can reduce campaign administration. A white-label platform can make the programme easier for an MSP to deliver under its own brand.
Those descriptions are operating models, not a claim that one category is always best. Compare the actual workflow from enrolment to report. Cyber Aware's platform comparison is a useful starting point because it puts white-label depth, seat model, multi-tenancy, phishing automation, frameworks and integrations in one view. Check the dated evidence for every vendor before making a purchase decision.
For Cyber Aware, the relevant capability is the combination of more than 100 phishing templates, difficulty levels from easy to hard, automatic failed-phishing enrolment and reporting for clicks and reports without credential harvesting. The security awareness training programme adds story-driven lessons and quizzes, so the simulation can sit inside a broader cadence rather than becoming an isolated test.
A practical rollout plan
Week one: establish the baseline
Choose one low-difficulty scenario that reflects a real workflow. Tell managers what the exercise is for, how reports are handled and what will not be collected. Measure reports as a positive outcome. Do not publish an individual leaderboard for a first campaign.
Weeks two to four: coach and repeat
Give clickers the explainer and follow-up lesson immediately. Review the questions people asked and whether reports reached the right team. Run a second campaign with a different scenario at the same level. If people can explain the verification rule and reporting route, introduce level two.
Month two: segment the next test
Separate the campaign by role. Finance can practise invoice and payment verification; executives can practise unusual access or approval requests; customer teams can practise document and account messages. Keep the learning objective consistent while changing the work context.
Month three: increase realism carefully
Move a group to level three only when the baseline behaviour is stable. Use a known service or internal process, but avoid live events that could cause confusion. Review exclusions, timing and support contacts before sending.
A gap assessment can help connect phishing results to wider issues such as unclear ownership, weak approval processes or missing access controls. The simulation tells you where behaviour needs help; the assessment helps explain which process should change around it.
What to measure
- Report rate: whether people use the safe reporting route.
- Click rate: how often a simulated request produces the risky action.
- Remediation completion: whether clickers finish the assigned coaching.
- Time to report: how quickly a concern reaches the responsible team.
- Repeat behaviour: whether the same person or group needs another intervention.
- Tier progression: whether a group can handle a more realistic scenario without losing reporting quality.
Avoid treating one campaign as a verdict. A harder campaign can produce more clicks without proving that the programme failed; the meaningful comparison is the same behaviour across comparable tiers and roles.
Troubleshooting
- The easy campaign has almost no reports. Make the reporting route visible and practise it separately; people may recognise the message but still not know what to do next.
- A hard campaign causes complaints. Return the group to the previous tier, explain the learning objective and remove any scenario that could be mistaken for a live instruction.
- Clickers receive no follow-up. Check automatic enrolment, course assignment and the owner responsible for remediation.
- Managers want a ranking of individuals. Use private support and group trends; the objective is safer behaviour, not public punishment.
- The click rate falls but real concerns are not reported. Measure the report route and reinforce that good-faith reports are useful.
FAQ
How many phishing difficulty levels are enough?
Three or four levels are usually easier to govern than a complicated scale. What matters is that each level has a clear purpose and the next step is based on behaviour, not a marketing label.
Should every employee receive the hardest simulation?
No. Match the scenario to role, experience and previous results. A staged programme teaches the verification habit before it tests that habit under pressure.
Is a click always a failure?
A click is a signal that the person needs a useful learning moment. A report, a quick escalation or a successful verification are equally important outcomes to track.
Can simulations collect passwords?
They should not. Use a safe landing page and confirm that reporting does not depend on collecting real credentials.
When should a group move up a tier?
Move up when the group can recognise the objective, report the message and complete follow-up learning consistently. Do not use a difficult campaign to compensate for an unclear process.
One last thing
Tiered phishing difficulty works when every level teaches the same safe habit in a more realistic setting. Choose the platform that makes that progression visible, keeps the exercise safe and gives a manager a clear next action after every result.
Related guides
- Phishing awareness
- Security awareness training
- Human risk reporting
- Security awareness platform comparison
Sources
- Phishing awareness programme, Cyber Aware, accessed August 2026.
- Security awareness training, Cyber Aware, accessed August 2026.
- Human Risk Reporting, Cyber Aware, accessed August 2026.