(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
Reporting a lost or stolen device
Uses secure file transfer instead of email attachment
Free!
Verifies sender email address
Someone mentions “Zero trust.”
Saying “If it seems too good to be true, it probably is”
Identifies a spoofed sender name
“If it seems too good to be true, it probably is”
Avoids sending sensitive info unencrypted
Recognizes when someone asks for too much information
Firewall rule allows “ANY/ANY” traffic
Avoids taking photos/screenshots of client data
Avoids sharing credentials with anyone
Unpatched system identified
Strong passphrase used (not just complex password)
Stores sensitive files securely
Locks computer when stepping away
Missing evidence for an audit test
Hovering over links before clicking
Knows how to report an incident
Shreds documents with personal or client info
Sensitive data sent via unencrypted email
Identifies suspicious activity on their account
Avoids public Wi‑Fi for work tasks
Deletes unexpected attachments
Recognizes a fake login page
Quarterly access review completed
Someone says “Let’s take that offline.”
Creates a strong passphrase (not just a password)
Knows the organization’s security policies exist
Updating software when prompted
Employee uses the “Report Phish” button
“Can you see my screen?”
“Shadow IT” app found
Missing BAA for a PHI‑handling vendor
Phishing email reported
Forwards unusual emails to the security team
“We’ll accept the risk” (without documentation 😉)
Updates software when prompted
Pet appears on camera
Excessive permissions (over‑privileged access)
Computer screen locked when away
Avoids downloading unknown applications
Using secure file transfer instead of email
Uses only approved tools for work
Recognizes an “urgent” or “act now” red flag
Data not classified correctly
Recognizes a scam or fake offer
Multi-factor authentication (MFA) enabled
Default password still in use
Reports a suspicious text message
High-risk vendor flagged
Vendor without recent SOC 2 report
Suspicious login alert
USB stick plugged into a corporate laptop
Uses company‑approved cloud storage
Declines to share information over the phone
Attending a security awareness training session
Double-checks external recipients before sending
Completes annual security training
Double-checking an external email recipient
Someone mentions “AI” or “Copilot.”
Knows not to plug unknown USBs into devices
Notices spelling/grammar errors in a suspicious email
Uses multi‑factor authentication
Validates payment or change requests through a second channel
Slide with a lot of tiny text
Recognizes a suspicious QR code
Deletes data they’re no longer authorized to retain