“Can yousee myscreen?”Usesmulti‑factorauthenticationSomeonementions“AI” or“Copilot.”AvoidspublicWi‑Fi forwork tasksPetappearsoncameraSomeonesays, “That’sa greatquestion.”USB stickplugged intoa corporatelaptopMentions“Thinkbeforeyou click”Someonesays “Let’stake thatoffline.”Double-checking anexternalemailrecipientReports asuspicioustextmessageDeletes datathey’re nolongerauthorized toretainUsescompany‑approvedcloud storageUnpatchedsystemidentifiedKnows theorganization’ssecuritypolicies existCompletesannualsecuritytrainingVendorwithoutrecent SOC2 reportDefaultpasswordstill in useNoticesspelling/grammarerrors in asuspicious emailStrongpassphraseused (notjust complexpassword)Reports asuspiciousemail“Thislooks likea phishingattempt”Missing BAAfor aPHI‑handlingvendorSharedcredentialsdiscoveredDouble-checksexternalrecipientsbefore sendingSensitivedata sent viaunencryptedemail“ShadowIT” appfoundValidatespayment orchangerequeststhrough asecond channelRecognizesan “urgent”or “act now”red flag“Sorry, Iwas onanothercall.”Shredsdocumentswithpersonal orclient info“If it seemstoo good tobe true, itprobably is”Public linksharingdisabledon a fileCreates astrongpassphrase(not just apassword)Forwardsunusualemails to thesecurityteamKnowshow toreport anincidentData notclassifiedcorrectlyHigh-riskvendorflaggedQuarterlyaccessreviewcompletedUpdatingsoftwarewhenpromptedAttending asecurityawarenesstrainingsessionSomeonementions“Zerotrust.”Multi-factorauthentication(MFA)enabledAvoids takingphotos/screenshotsof client dataIdentifiesa spoofedsendernameFree!Hoveringover linksbeforeclickingSomeone’sconnectionfreezesmid‑sentenceReportinga lost orstolendeviceUses securefile transferinstead ofemailattachmentMissingevidencefor anaudit testAvoidssendingsensitive infounencryptedUpdatessoftwarewhenpromptedRecognizeswhensomeone asksfor too muchinformationRecognizesa fake loginpageVerifying apayment/changerequest viaphoneDeletesunexpectedattachmentsUsing securefile transferinstead ofemailRecognizesasuspiciousQR codeAvoidssharingcredentialswith anyoneLockscomputerwhensteppingawayRecognizesa scam orfake offerNodocumentedincidentresponseplan“You’reonmute.”Declines toshareinformationover thephoneKnows not toplugunknownUSBs intodevices“We’ll acceptthe risk”(withoutdocumentation😉)StoressensitivefilessecurelyUses onlyapprovedtools forworkComputerscreenlockedwhen awayAvoidsdownloadingunknownapplicationsSlide witha lot oftiny textSuspiciouslogin alertIdentifiessuspiciousactivity ontheir accountSaying “If itseems toogood to betrue, itprobably is”Excessivepermissions(over‑privilegedaccess)Firewallrule allows“ANY/ANY”trafficPhishingemailreportedEmployeeuses the“ReportPhish”buttonVerifiessenderemailaddressUsesapprovedsystems forwork files“Can yousee myscreen?”Usesmulti‑factorauthenticationSomeonementions“AI” or“Copilot.”AvoidspublicWi‑Fi forwork tasksPetappearsoncameraSomeonesays, “That’sa greatquestion.”USB stickplugged intoa corporatelaptopMentions“Thinkbeforeyou click”Someonesays “Let’stake thatoffline.”Double-checking anexternalemailrecipientReports asuspicioustextmessageDeletes datathey’re nolongerauthorized toretainUsescompany‑approvedcloud storageUnpatchedsystemidentifiedKnows theorganization’ssecuritypolicies existCompletesannualsecuritytrainingVendorwithoutrecent SOC2 reportDefaultpasswordstill in useNoticesspelling/grammarerrors in asuspicious emailStrongpassphraseused (notjust complexpassword)Reports asuspiciousemail“Thislooks likea phishingattempt”Missing BAAfor aPHI‑handlingvendorSharedcredentialsdiscoveredDouble-checksexternalrecipientsbefore sendingSensitivedata sent viaunencryptedemail“ShadowIT” appfoundValidatespayment orchangerequeststhrough asecond channelRecognizesan “urgent”or “act now”red flag“Sorry, Iwas onanothercall.”Shredsdocumentswithpersonal orclient info“If it seemstoo good tobe true, itprobably is”Public linksharingdisabledon a fileCreates astrongpassphrase(not just apassword)Forwardsunusualemails to thesecurityteamKnowshow toreport anincidentData notclassifiedcorrectlyHigh-riskvendorflaggedQuarterlyaccessreviewcompletedUpdatingsoftwarewhenpromptedAttending asecurityawarenesstrainingsessionSomeonementions“Zerotrust.”Multi-factorauthentication(MFA)enabledAvoids takingphotos/screenshotsof client dataIdentifiesa spoofedsendernameFree!Hoveringover linksbeforeclickingSomeone’sconnectionfreezesmid‑sentenceReportinga lost orstolendeviceUses securefile transferinstead ofemailattachmentMissingevidencefor anaudit testAvoidssendingsensitive infounencryptedUpdatessoftwarewhenpromptedRecognizeswhensomeone asksfor too muchinformationRecognizesa fake loginpageVerifying apayment/changerequest viaphoneDeletesunexpectedattachmentsUsing securefile transferinstead ofemailRecognizesasuspiciousQR codeAvoidssharingcredentialswith anyoneLockscomputerwhensteppingawayRecognizesa scam orfake offerNodocumentedincidentresponseplan“You’reonmute.”Declines toshareinformationover thephoneKnows not toplugunknownUSBs intodevices“We’ll acceptthe risk”(withoutdocumentation😉)StoressensitivefilessecurelyUses onlyapprovedtools forworkComputerscreenlockedwhen awayAvoidsdownloadingunknownapplicationsSlide witha lot oftiny textSuspiciouslogin alertIdentifiessuspiciousactivity ontheir accountSaying “If itseems toogood to betrue, itprobably is”Excessivepermissions(over‑privilegedaccess)Firewallrule allows“ANY/ANY”trafficPhishingemailreportedEmployeeuses the“ReportPhish”buttonVerifiessenderemailaddressUsesapprovedsystems forwork files

General Security Awareness - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
  1. “Can you see my screen?”
  2. Uses multi‑factor authentication
  3. Someone mentions “AI” or “Copilot.”
  4. Avoids public Wi‑Fi for work tasks
  5. Pet appears on camera
  6. Someone says, “That’s a great question.”
  7. USB stick plugged into a corporate laptop
  8. Mentions “Think before you click”
  9. Someone says “Let’s take that offline.”
  10. Double-checking an external email recipient
  11. Reports a suspicious text message
  12. Deletes data they’re no longer authorized to retain
  13. Uses company‑approved cloud storage
  14. Unpatched system identified
  15. Knows the organization’s security policies exist
  16. Completes annual security training
  17. Vendor without recent SOC 2 report
  18. Default password still in use
  19. Notices spelling/grammar errors in a suspicious email
  20. Strong passphrase used (not just complex password)
  21. Reports a suspicious email
  22. “This looks like a phishing attempt”
  23. Missing BAA for a PHI‑handling vendor
  24. Shared credentials discovered
  25. Double-checks external recipients before sending
  26. Sensitive data sent via unencrypted email
  27. “Shadow IT” app found
  28. Validates payment or change requests through a second channel
  29. Recognizes an “urgent” or “act now” red flag
  30. “Sorry, I was on another call.”
  31. Shreds documents with personal or client info
  32. “If it seems too good to be true, it probably is”
  33. Public link sharing disabled on a file
  34. Creates a strong passphrase (not just a password)
  35. Forwards unusual emails to the security team
  36. Knows how to report an incident
  37. Data not classified correctly
  38. High-risk vendor flagged
  39. Quarterly access review completed
  40. Updating software when prompted
  41. Attending a security awareness training session
  42. Someone mentions “Zero trust.”
  43. Multi-factor authentication (MFA) enabled
  44. Avoids taking photos/screenshots of client data
  45. Identifies a spoofed sender name
  46. Free!
  47. Hovering over links before clicking
  48. Someone’s connection freezes mid‑sentence
  49. Reporting a lost or stolen device
  50. Uses secure file transfer instead of email attachment
  51. Missing evidence for an audit test
  52. Avoids sending sensitive info unencrypted
  53. Updates software when prompted
  54. Recognizes when someone asks for too much information
  55. Recognizes a fake login page
  56. Verifying a payment/change request via phone
  57. Deletes unexpected attachments
  58. Using secure file transfer instead of email
  59. Recognizes a suspicious QR code
  60. Avoids sharing credentials with anyone
  61. Locks computer when stepping away
  62. Recognizes a scam or fake offer
  63. No documented incident response plan
  64. “You’re on mute.”
  65. Declines to share information over the phone
  66. Knows not to plug unknown USBs into devices
  67. “We’ll accept the risk” (without documentation 😉)
  68. Stores sensitive files securely
  69. Uses only approved tools for work
  70. Computer screen locked when away
  71. Avoids downloading unknown applications
  72. Slide with a lot of tiny text
  73. Suspicious login alert
  74. Identifies suspicious activity on their account
  75. Saying “If it seems too good to be true, it probably is”
  76. Excessive permissions (over‑privileged access)
  77. Firewall rule allows “ANY/ANY” traffic
  78. Phishing email reported
  79. Employee uses the “Report Phish” button
  80. Verifies sender email address
  81. Uses approved systems for work files