King of Cybersecurity: Free Phishing Awareness Posters and Cybersecurity ResourcesCybersecurity awareness is often presented through compulsory training modules, policy documents and lists of warnings. These materials can communicate the correct information, but employees must also notice, understand and remember it when a suspicious email or unexpected request arrives. King of Cybersecurity is a cybersecurity awareness website that uses an illustrated fictional medieval court to explain modern security risks. Its stories and characters make mistakes involving phishing, passwords, ransomware, backups, artificial intelligence and other security subjects. The fictional court provides the humour, while the accompanying guidance explains the practical action readers should take. Created by cybersecurity professional and technology leader Shakel Ahmed, King of Cybersecurity publishes illustrated satire alongside free security awareness resources for employees, small businesses and organisations running internal awareness campaigns. These materials are available through the Royal Armoury at https://kingofcybersecurity.com/royal-armoury/. The objective is to use humour, recognisable situations and recurring characters to attract attention before delivering practical advice that people can apply. Free cybersecurity awareness resourcesThe Royal Armoury is a collection of ready-to-use cybersecurity awareness materials. It includes printable posters, illustrated memes and a presentation deck with speaker notes. The collection was introduced ahead of Cybersecurity Awareness Month, but its subjects are relevant throughout the year. Organisations can use the resources when introducing new employees, running internal campaigns or reinforcing individual security messages. The materials are available in practical formats, including:
This makes the collection accessible to smaller organisations, IT teams and security-awareness professionals that may not have the time or design resources to create a complete campaign internally. Rather than only stating that employees should “be cyber aware,” the posters identify particular warning signs and decisions. Subjects include manufactured urgency in phishing messages, sender impersonation, disguised links, gift-card fraud, predictable password patterns and multi-factor authentication. Four common phishing warning signsOne of the Royal Armoury posters presents a suspicious email as a wanted criminal charged with four phishing offences: manufacturing urgency, impersonating a trusted sender, disguising links and demanding gift cards. Each charge is paired with practical advice explaining what the recipient should do. Manufacturing urgencyPhishing messages frequently try to create pressure. The recipient may be told that an account will be closed, a payment has failed or an important opportunity will disappear unless immediate action is taken. This urgency is often part of the attack. It is intended to make the recipient react before checking the message carefully. Slowing down can interrupt that process. Before following instructions, the recipient can consider whether the request was expected, whether the situation makes sense and whether the claimed sender can be contacted through another route. Impersonating a trusted senderA familiar display name does not prove that a message came from the person or organisation shown. Attackers can use names, logos and writing styles that make a message appear credible. The underlying email address may reveal a misspelling, an unfamiliar domain or an unrelated account. However, an address that looks plausible should not be treated as definitive proof either. When a request involves money, credentials, sensitive information or an unusual action, the recipient should verify it independently. That might mean calling the person using a known telephone number or beginning a new conversation through an established communication channel. The important point is not to use contact information supplied by the suspicious message itself. Disguising a linkThe visible words in a link may conceal a different destination. A button labelled “review document” or “sign in” can direct the recipient to a website controlled by an attacker. Previewing the address before opening it may expose misspellings, unexpected domains or a destination unrelated to the claimed sender. On devices where previewing is difficult, the safer option may be to avoid the link and reach the service through its official website or application. Employees should also be encouraged to report suspicious links rather than investigating them unnecessarily. Demanding gift cardsAn unexpected request to purchase gift cards and send the codes is a well-known indicator of fraud. The attacker may impersonate a senior colleague and claim to be unavailable for a telephone call. Urgency, authority and secrecy are then used to discourage verification. Gift-card codes can be transferred quickly and are difficult to recover once disclosed. Employees should treat these requests as fraudulent and report them through their organisation’s established process. The poster brings these four techniques together in one visual resource. It gives employees a simple sequence to remember: pause, inspect, verify and report. Reporting suspicious emails and text messagesAwareness is more valuable when employees know what action to take after recognising something suspicious. For UK audiences, suspicious emails can be forwarded to the National Cyber Security Centre’s Suspicious Email Reporting Service at [email protected]. Suspicious text messages can be forwarded to 7726, a reporting service provided by mobile operators. Organisations should also give employees a clear internal reporting route. This might be a dedicated mailbox, a reporting button within the email system or a service-desk process. Employees should know how to report a message even if they have already opened a link, downloaded a file or supplied information. Prompt reporting can give the organisation an opportunity to investigate, protect affected accounts and warn other recipients. An effective reporting culture should therefore make it easy for people to ask for help without fearing embarrassment or blame. Practical password security guidanceAnother Royal Armoury poster uses a fictional horse character to judge six example passwords. The character provides the humour, while the accompanying guidance explains why each password is accepted or rejected. The examples show the difference between passwords that appear complicated and those that are more defensible in practice. Seasonal words, predictable number sequences and common character substitutions may satisfy basic complexity rules while remaining relatively easy to anticipate. Replacing a letter with a similar-looking number does not automatically make a password strong. Attackers and password-cracking tools are familiar with common substitutions and patterns. The poster instead favours a long passphrase made from unrelated words and a long password generated by a password manager. This reflects the practical need to create credentials that are long, difficult to guess and unique to each service. The UK National Cyber Security Centre recommends combining random words as one way to create a password that is both strong enough and easier to remember. It also identifies password managers as a way to generate and store strong passwords. Password reuse is especially important to address. When the same password is used for several accounts, a compromise at one service can place the others at risk. A password manager can reduce the burden of remembering separate credentials and make unique passwords more practical. The underlying advice concerns password length, predictability, uniqueness and secure management. Explaining multi-factor authenticationThe Royal Armoury also includes a poster covering multi-factor authentication, commonly shortened to MFA. MFA adds another verification step instead of relying on a password alone. Depending on the service, this might involve an authenticator application, a security key, a code or verification performed through a trusted device. This matters because passwords can be exposed through phishing, malware, password reuse or a compromised service. An additional authentication factor can make it harder for an attacker to access an account using only a stolen password. Awareness material should not suggest that MFA makes an account invulnerable. Attackers may still try to trick users into disclosing authentication codes or approving sign-in requests they did not initiate. Employees should understand that an unexpected authentication notification should not be approved automatically. It could indicate that someone already possesses the associated password and is attempting to complete the sign-in process. The practical message is to enable MFA where it is available, protect the authentication method and reject unexpected requests. Illustrated cybersecurity chroniclesBeyond the Royal Armoury, King of Cybersecurity publishes illustrated chronicles about the decisions organisations and employees make around security. The fictional court has encountered phishing simulations, untested backups, ransomware, password policies, artificial intelligence and two-factor authentication. These stories use exaggerated situations to introduce genuine questions. A story about an untested backup can highlight the difference between possessing a backup and knowing that information can be restored successfully. A chronicle about artificial intelligence can introduce questions about confidential data, inaccurate outputs and the adoption of tools without appropriate review. The medieval setting creates distance between the reader and the mistake. Instead of identifying a particular employee as the example of what not to do, the fictional court makes the error. Readers can then consider how the same behaviour might appear in a modern workplace. Using the resources in an organisationThe Royal Armoury materials can be used individually or as part of a wider awareness programme. A phishing poster could accompany an internal message about reporting suspicious emails. The password and MFA materials could support an account-security campaign. An illustrated chronicle could introduce a short discussion during a team meeting. The presentation deck can be used for an internal briefing, employee onboarding or a Cybersecurity Awareness Month event. Its speaker notes allow the presenter to expand on the visual messages without placing excessive text on each slide. Organisations could also release one resource at a time. A short campaign might begin with phishing recognition, continue with password management and finish with multi-factor authentication. This gives each subject its own moment rather than presenting employees with every message at once. Awareness resources should complement technical and organisational controls. Email filtering, access management, secure configuration, tested backups, incident procedures and strong authentication remain essential. The surrounding communication should also reflect the organisation’s environment. Employees need to know where to report suspicious activity, whom to contact when a financial request seems unusual and what to do after making a mistake. Practical cybersecurity awareness with a memorable identityKing of Cybersecurity combines a distinctive fictional setting with practical cybersecurity guidance and free awareness materials. Its phishing poster does more than warn that phishing exists. It identifies urgency, impersonation, disguised links and gift-card demands, then gives the reader actions to take. Its password material challenges predictable patterns and introduces stronger alternatives. Its authentication resource explains why accounts benefit from protection beyond a password. The medieval court and recurring characters give the project a recognisable identity, while the Royal Armoury provides resources that organisations can put into practical use. The free cybersecurity awareness posters, illustrated resources, presentation materials and chronicles are available from King of Cybersecurity at https://kingofcybersecurity.com/royal-armoury/. |