Usesapprovedsystems forwork filesEmployeeuses the“ReportPhish”buttonData notclassifiedcorrectlySaying “If itseems toogood to betrue, itprobably is”Double-checksexternalrecipientsbefore sendingVendorwithoutrecent SOC2 reportPhishingemailreportedPublic linksharingdisabledon a file“If it seemstoo good tobe true, itprobably is”RecognizesasuspiciousQR codeSomeonesays “Let’stake thatoffline.”Declines toshareinformationover thephoneRecognizesa fake loginpageSomeone’sconnectionfreezesmid‑sentenceReportinga lost orstolendeviceKnows theorganization’ssecuritypolicies existAvoidspublicWi‑Fi forwork tasksFirewallrule allows“ANY/ANY”trafficIdentifiessuspiciousactivity ontheir accountUsing securefile transferinstead ofemailDouble-checking anexternalemailrecipientStrongpassphraseused (notjust complexpassword)Sensitivedata sent viaunencryptedemailVerifiessenderemailaddress“You’reonmute.”Identifiesa spoofedsendernameAvoidssendingsensitive infounencryptedDeletesunexpectedattachmentsDefaultpasswordstill in useAttending asecurityawarenesstrainingsessionUpdatingsoftwarewhenpromptedNodocumentedincidentresponseplanExcessivepermissions(over‑privilegedaccess)Hoveringover linksbeforeclickingReports asuspiciousemailComputerscreenlockedwhen awayCompletesannualsecuritytrainingHigh-riskvendorflaggedSomeonesays, “That’sa greatquestion.”Petappearsoncamera“Thislooks likea phishingattempt”Free!“Sorry, Iwas onanothercall.”StoressensitivefilessecurelySomeonementions“Zerotrust.”Knows not toplugunknownUSBs intodevicesMissing BAAfor aPHI‑handlingvendorUSB stickplugged intoa corporatelaptopUpdatessoftwarewhenpromptedMissingevidencefor anaudit testForwardsunusualemails to thesecurityteamSomeonementions“AI” or“Copilot.”Reports asuspicioustextmessageKnowshow toreport anincidentQuarterlyaccessreviewcompletedRecognizesan “urgent”or “act now”red flagValidatespayment orchangerequeststhrough asecond channelUsesmulti‑factorauthenticationAvoidssharingcredentialswith anyoneAvoidsdownloadingunknownapplicationsUses securefile transferinstead ofemailattachmentUnpatchedsystemidentifiedRecognizesa scam orfake offer“ShadowIT” appfound“Can yousee myscreen?”Mentions“Thinkbeforeyou click”Usescompany‑approvedcloud storageSuspiciouslogin alertVerifying apayment/changerequest viaphoneDeletes datathey’re nolongerauthorized toretainSlide witha lot oftiny textShredsdocumentswithpersonal orclient infoCreates astrongpassphrase(not just apassword)Multi-factorauthentication(MFA)enabledLockscomputerwhensteppingaway“We’ll acceptthe risk”(withoutdocumentation😉)Noticesspelling/grammarerrors in asuspicious emailSharedcredentialsdiscoveredAvoids takingphotos/screenshotsof client dataRecognizeswhensomeone asksfor too muchinformationUses onlyapprovedtools forworkUsesapprovedsystems forwork filesEmployeeuses the“ReportPhish”buttonData notclassifiedcorrectlySaying “If itseems toogood to betrue, itprobably is”Double-checksexternalrecipientsbefore sendingVendorwithoutrecent SOC2 reportPhishingemailreportedPublic linksharingdisabledon a file“If it seemstoo good tobe true, itprobably is”RecognizesasuspiciousQR codeSomeonesays “Let’stake thatoffline.”Declines toshareinformationover thephoneRecognizesa fake loginpageSomeone’sconnectionfreezesmid‑sentenceReportinga lost orstolendeviceKnows theorganization’ssecuritypolicies existAvoidspublicWi‑Fi forwork tasksFirewallrule allows“ANY/ANY”trafficIdentifiessuspiciousactivity ontheir accountUsing securefile transferinstead ofemailDouble-checking anexternalemailrecipientStrongpassphraseused (notjust complexpassword)Sensitivedata sent viaunencryptedemailVerifiessenderemailaddress“You’reonmute.”Identifiesa spoofedsendernameAvoidssendingsensitive infounencryptedDeletesunexpectedattachmentsDefaultpasswordstill in useAttending asecurityawarenesstrainingsessionUpdatingsoftwarewhenpromptedNodocumentedincidentresponseplanExcessivepermissions(over‑privilegedaccess)Hoveringover linksbeforeclickingReports asuspiciousemailComputerscreenlockedwhen awayCompletesannualsecuritytrainingHigh-riskvendorflaggedSomeonesays, “That’sa greatquestion.”Petappearsoncamera“Thislooks likea phishingattempt”Free!“Sorry, Iwas onanothercall.”StoressensitivefilessecurelySomeonementions“Zerotrust.”Knows not toplugunknownUSBs intodevicesMissing BAAfor aPHI‑handlingvendorUSB stickplugged intoa corporatelaptopUpdatessoftwarewhenpromptedMissingevidencefor anaudit testForwardsunusualemails to thesecurityteamSomeonementions“AI” or“Copilot.”Reports asuspicioustextmessageKnowshow toreport anincidentQuarterlyaccessreviewcompletedRecognizesan “urgent”or “act now”red flagValidatespayment orchangerequeststhrough asecond channelUsesmulti‑factorauthenticationAvoidssharingcredentialswith anyoneAvoidsdownloadingunknownapplicationsUses securefile transferinstead ofemailattachmentUnpatchedsystemidentifiedRecognizesa scam orfake offer“ShadowIT” appfound“Can yousee myscreen?”Mentions“Thinkbeforeyou click”Usescompany‑approvedcloud storageSuspiciouslogin alertVerifying apayment/changerequest viaphoneDeletes datathey’re nolongerauthorized toretainSlide witha lot oftiny textShredsdocumentswithpersonal orclient infoCreates astrongpassphrase(not just apassword)Multi-factorauthentication(MFA)enabledLockscomputerwhensteppingaway“We’ll acceptthe risk”(withoutdocumentation😉)Noticesspelling/grammarerrors in asuspicious emailSharedcredentialsdiscoveredAvoids takingphotos/screenshotsof client dataRecognizeswhensomeone asksfor too muchinformationUses onlyapprovedtools forwork

General Security Awareness - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
  1. Uses approved systems for work files
  2. Employee uses the “Report Phish” button
  3. Data not classified correctly
  4. Saying “If it seems too good to be true, it probably is”
  5. Double-checks external recipients before sending
  6. Vendor without recent SOC 2 report
  7. Phishing email reported
  8. Public link sharing disabled on a file
  9. “If it seems too good to be true, it probably is”
  10. Recognizes a suspicious QR code
  11. Someone says “Let’s take that offline.”
  12. Declines to share information over the phone
  13. Recognizes a fake login page
  14. Someone’s connection freezes mid‑sentence
  15. Reporting a lost or stolen device
  16. Knows the organization’s security policies exist
  17. Avoids public Wi‑Fi for work tasks
  18. Firewall rule allows “ANY/ANY” traffic
  19. Identifies suspicious activity on their account
  20. Using secure file transfer instead of email
  21. Double-checking an external email recipient
  22. Strong passphrase used (not just complex password)
  23. Sensitive data sent via unencrypted email
  24. Verifies sender email address
  25. “You’re on mute.”
  26. Identifies a spoofed sender name
  27. Avoids sending sensitive info unencrypted
  28. Deletes unexpected attachments
  29. Default password still in use
  30. Attending a security awareness training session
  31. Updating software when prompted
  32. No documented incident response plan
  33. Excessive permissions (over‑privileged access)
  34. Hovering over links before clicking
  35. Reports a suspicious email
  36. Computer screen locked when away
  37. Completes annual security training
  38. High-risk vendor flagged
  39. Someone says, “That’s a great question.”
  40. Pet appears on camera
  41. “This looks like a phishing attempt”
  42. Free!
  43. “Sorry, I was on another call.”
  44. Stores sensitive files securely
  45. Someone mentions “Zero trust.”
  46. Knows not to plug unknown USBs into devices
  47. Missing BAA for a PHI‑handling vendor
  48. USB stick plugged into a corporate laptop
  49. Updates software when prompted
  50. Missing evidence for an audit test
  51. Forwards unusual emails to the security team
  52. Someone mentions “AI” or “Copilot.”
  53. Reports a suspicious text message
  54. Knows how to report an incident
  55. Quarterly access review completed
  56. Recognizes an “urgent” or “act now” red flag
  57. Validates payment or change requests through a second channel
  58. Uses multi‑factor authentication
  59. Avoids sharing credentials with anyone
  60. Avoids downloading unknown applications
  61. Uses secure file transfer instead of email attachment
  62. Unpatched system identified
  63. Recognizes a scam or fake offer
  64. “Shadow IT” app found
  65. “Can you see my screen?”
  66. Mentions “Think before you click”
  67. Uses company‑approved cloud storage
  68. Suspicious login alert
  69. Verifying a payment/change request via phone
  70. Deletes data they’re no longer authorized to retain
  71. Slide with a lot of tiny text
  72. Shreds documents with personal or client info
  73. Creates a strong passphrase (not just a password)
  74. Multi-factor authentication (MFA) enabled
  75. Locks computer when stepping away
  76. “We’ll accept the risk” (without documentation 😉)
  77. Notices spelling/grammar errors in a suspicious email
  78. Shared credentials discovered
  79. Avoids taking photos/screenshots of client data
  80. Recognizes when someone asks for too much information
  81. Uses only approved tools for work