(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
Uses approved systems for work files
Employee uses the “Report Phish” button
Data not classified correctly
Saying “If it seems too good to be true, it probably is”
Double-checks external recipients before sending
Vendor without recent SOC 2 report
Phishing email reported
Public link sharing disabled on a file
“If it seems too good to be true, it probably is”
Recognizes a suspicious QR code
Someone says “Let’s take that offline.”
Declines to share information over the phone
Recognizes a fake login page
Someone’s connection freezes mid‑sentence
Reporting a lost or stolen device
Knows the organization’s security policies exist
Avoids public Wi‑Fi for work tasks
Firewall rule allows “ANY/ANY” traffic
Identifies suspicious activity on their account
Using secure file transfer instead of email
Double-checking an external email recipient
Strong passphrase used (not just complex password)
Sensitive data sent via unencrypted email
Verifies sender email address
“You’re on mute.”
Identifies a spoofed sender name
Avoids sending sensitive info unencrypted
Deletes unexpected attachments
Default password still in use
Attending a security awareness training session
Updating software when prompted
No documented incident response plan
Excessive permissions (over‑privileged access)
Hovering over links before clicking
Reports a suspicious email
Computer screen locked when away
Completes annual security training
High-risk vendor flagged
Someone says, “That’s a great question.”
Pet appears on camera
“This looks like a phishing attempt”
Free!
“Sorry, I was on another call.”
Stores sensitive files securely
Someone mentions “Zero trust.”
Knows not to plug unknown USBs into devices
Missing BAA for a PHI‑handling vendor
USB stick plugged into a corporate laptop
Updates software when prompted
Missing evidence for an audit test
Forwards unusual emails to the security team
Someone mentions “AI” or “Copilot.”
Reports a suspicious text message
Knows how to report an incident
Quarterly access review completed
Recognizes an “urgent” or “act now” red flag
Validates payment or change requests through a second channel
Uses multi‑factor authentication
Avoids sharing credentials with anyone
Avoids downloading unknown applications
Uses secure file transfer instead of email attachment
Unpatched system identified
Recognizes a scam or fake offer
“Shadow IT” app found
“Can you see my screen?”
Mentions “Think before you click”
Uses company‑approved cloud storage
Suspicious login alert
Verifying a payment/change request via phone
Deletes data they’re no longer authorized to retain
Slide with a lot of tiny text
Shreds documents with personal or client info
Creates a strong passphrase (not just a password)
Multi-factor authentication (MFA) enabled
Locks computer when stepping away
“We’ll accept the risk” (without documentation 😉)
Notices spelling/grammar errors in a suspicious email
Shared credentials discovered
Avoids taking photos/screenshots of client data
Recognizes when someone asks for too much information