Reportinga lost orstolendeviceUses securefile transferinstead ofemailattachmentFree!VerifiessenderemailaddressSomeonementions“Zerotrust.”Saying “If itseems toogood to betrue, itprobably is”Identifiesa spoofedsendername“If it seemstoo good tobe true, itprobably is”Avoidssendingsensitive infounencryptedRecognizeswhensomeone asksfor too muchinformationFirewallrule allows“ANY/ANY”trafficAvoids takingphotos/screenshotsof client dataAvoidssharingcredentialswith anyoneUnpatchedsystemidentifiedStrongpassphraseused (notjust complexpassword)StoressensitivefilessecurelyLockscomputerwhensteppingawayMissingevidencefor anaudit testHoveringover linksbeforeclickingKnowshow toreport anincidentShredsdocumentswithpersonal orclient infoSensitivedata sent viaunencryptedemailIdentifiessuspiciousactivity ontheir accountAvoidspublicWi‑Fi forwork tasksDeletesunexpectedattachmentsRecognizesa fake loginpageQuarterlyaccessreviewcompletedSomeonesays “Let’stake thatoffline.”Creates astrongpassphrase(not just apassword)Knows theorganization’ssecuritypolicies existUpdatingsoftwarewhenpromptedEmployeeuses the“ReportPhish”button“Can yousee myscreen?”“ShadowIT” appfoundMissing BAAfor aPHI‑handlingvendorPhishingemailreportedForwardsunusualemails to thesecurityteam“We’ll acceptthe risk”(withoutdocumentation😉)UpdatessoftwarewhenpromptedPetappearsoncameraExcessivepermissions(over‑privilegedaccess)Computerscreenlockedwhen awayAvoidsdownloadingunknownapplicationsUsing securefile transferinstead ofemailUses onlyapprovedtools forworkRecognizesan “urgent”or “act now”red flagData notclassifiedcorrectlyRecognizesa scam orfake offerMulti-factorauthentication(MFA)enabledDefaultpasswordstill in useReports asuspicioustextmessageHigh-riskvendorflaggedVendorwithoutrecent SOC2 reportSuspiciouslogin alertUSB stickplugged intoa corporatelaptopUsescompany‑approvedcloud storageDeclines toshareinformationover thephoneAttending asecurityawarenesstrainingsessionDouble-checksexternalrecipientsbefore sendingCompletesannualsecuritytrainingDouble-checking anexternalemailrecipientSomeonementions“AI” or“Copilot.”Knows not toplugunknownUSBs intodevicesNoticesspelling/grammarerrors in asuspicious emailUsesmulti‑factorauthenticationValidatespayment orchangerequeststhrough asecond channelSlide witha lot oftiny textRecognizesasuspiciousQR codeDeletes datathey’re nolongerauthorized toretainPublic linksharingdisabledon a fileReports asuspiciousemail“You’reonmute.”Someonesays, “That’sa greatquestion.”Mentions“Thinkbeforeyou click”Nodocumentedincidentresponseplan“Sorry, Iwas onanothercall.”“Thislooks likea phishingattempt”Verifying apayment/changerequest viaphoneSharedcredentialsdiscoveredSomeone’sconnectionfreezesmid‑sentenceUsesapprovedsystems forwork filesReportinga lost orstolendeviceUses securefile transferinstead ofemailattachmentFree!VerifiessenderemailaddressSomeonementions“Zerotrust.”Saying “If itseems toogood to betrue, itprobably is”Identifiesa spoofedsendername“If it seemstoo good tobe true, itprobably is”Avoidssendingsensitive infounencryptedRecognizeswhensomeone asksfor too muchinformationFirewallrule allows“ANY/ANY”trafficAvoids takingphotos/screenshotsof client dataAvoidssharingcredentialswith anyoneUnpatchedsystemidentifiedStrongpassphraseused (notjust complexpassword)StoressensitivefilessecurelyLockscomputerwhensteppingawayMissingevidencefor anaudit testHoveringover linksbeforeclickingKnowshow toreport anincidentShredsdocumentswithpersonal orclient infoSensitivedata sent viaunencryptedemailIdentifiessuspiciousactivity ontheir accountAvoidspublicWi‑Fi forwork tasksDeletesunexpectedattachmentsRecognizesa fake loginpageQuarterlyaccessreviewcompletedSomeonesays “Let’stake thatoffline.”Creates astrongpassphrase(not just apassword)Knows theorganization’ssecuritypolicies existUpdatingsoftwarewhenpromptedEmployeeuses the“ReportPhish”button“Can yousee myscreen?”“ShadowIT” appfoundMissing BAAfor aPHI‑handlingvendorPhishingemailreportedForwardsunusualemails to thesecurityteam“We’ll acceptthe risk”(withoutdocumentation😉)UpdatessoftwarewhenpromptedPetappearsoncameraExcessivepermissions(over‑privilegedaccess)Computerscreenlockedwhen awayAvoidsdownloadingunknownapplicationsUsing securefile transferinstead ofemailUses onlyapprovedtools forworkRecognizesan “urgent”or “act now”red flagData notclassifiedcorrectlyRecognizesa scam orfake offerMulti-factorauthentication(MFA)enabledDefaultpasswordstill in useReports asuspicioustextmessageHigh-riskvendorflaggedVendorwithoutrecent SOC2 reportSuspiciouslogin alertUSB stickplugged intoa corporatelaptopUsescompany‑approvedcloud storageDeclines toshareinformationover thephoneAttending asecurityawarenesstrainingsessionDouble-checksexternalrecipientsbefore sendingCompletesannualsecuritytrainingDouble-checking anexternalemailrecipientSomeonementions“AI” or“Copilot.”Knows not toplugunknownUSBs intodevicesNoticesspelling/grammarerrors in asuspicious emailUsesmulti‑factorauthenticationValidatespayment orchangerequeststhrough asecond channelSlide witha lot oftiny textRecognizesasuspiciousQR codeDeletes datathey’re nolongerauthorized toretainPublic linksharingdisabledon a fileReports asuspiciousemail“You’reonmute.”Someonesays, “That’sa greatquestion.”Mentions“Thinkbeforeyou click”Nodocumentedincidentresponseplan“Sorry, Iwas onanothercall.”“Thislooks likea phishingattempt”Verifying apayment/changerequest viaphoneSharedcredentialsdiscoveredSomeone’sconnectionfreezesmid‑sentenceUsesapprovedsystems forwork files

General Security Awareness - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
  1. Reporting a lost or stolen device
  2. Uses secure file transfer instead of email attachment
  3. Free!
  4. Verifies sender email address
  5. Someone mentions “Zero trust.”
  6. Saying “If it seems too good to be true, it probably is”
  7. Identifies a spoofed sender name
  8. “If it seems too good to be true, it probably is”
  9. Avoids sending sensitive info unencrypted
  10. Recognizes when someone asks for too much information
  11. Firewall rule allows “ANY/ANY” traffic
  12. Avoids taking photos/screenshots of client data
  13. Avoids sharing credentials with anyone
  14. Unpatched system identified
  15. Strong passphrase used (not just complex password)
  16. Stores sensitive files securely
  17. Locks computer when stepping away
  18. Missing evidence for an audit test
  19. Hovering over links before clicking
  20. Knows how to report an incident
  21. Shreds documents with personal or client info
  22. Sensitive data sent via unencrypted email
  23. Identifies suspicious activity on their account
  24. Avoids public Wi‑Fi for work tasks
  25. Deletes unexpected attachments
  26. Recognizes a fake login page
  27. Quarterly access review completed
  28. Someone says “Let’s take that offline.”
  29. Creates a strong passphrase (not just a password)
  30. Knows the organization’s security policies exist
  31. Updating software when prompted
  32. Employee uses the “Report Phish” button
  33. “Can you see my screen?”
  34. “Shadow IT” app found
  35. Missing BAA for a PHI‑handling vendor
  36. Phishing email reported
  37. Forwards unusual emails to the security team
  38. “We’ll accept the risk” (without documentation 😉)
  39. Updates software when prompted
  40. Pet appears on camera
  41. Excessive permissions (over‑privileged access)
  42. Computer screen locked when away
  43. Avoids downloading unknown applications
  44. Using secure file transfer instead of email
  45. Uses only approved tools for work
  46. Recognizes an “urgent” or “act now” red flag
  47. Data not classified correctly
  48. Recognizes a scam or fake offer
  49. Multi-factor authentication (MFA) enabled
  50. Default password still in use
  51. Reports a suspicious text message
  52. High-risk vendor flagged
  53. Vendor without recent SOC 2 report
  54. Suspicious login alert
  55. USB stick plugged into a corporate laptop
  56. Uses company‑approved cloud storage
  57. Declines to share information over the phone
  58. Attending a security awareness training session
  59. Double-checks external recipients before sending
  60. Completes annual security training
  61. Double-checking an external email recipient
  62. Someone mentions “AI” or “Copilot.”
  63. Knows not to plug unknown USBs into devices
  64. Notices spelling/grammar errors in a suspicious email
  65. Uses multi‑factor authentication
  66. Validates payment or change requests through a second channel
  67. Slide with a lot of tiny text
  68. Recognizes a suspicious QR code
  69. Deletes data they’re no longer authorized to retain
  70. Public link sharing disabled on a file
  71. Reports a suspicious email
  72. “You’re on mute.”
  73. Someone says, “That’s a great question.”
  74. Mentions “Think before you click”
  75. No documented incident response plan
  76. “Sorry, I was on another call.”
  77. “This looks like a phishing attempt”
  78. Verifying a payment/change request via phone
  79. Shared credentials discovered
  80. Someone’s connection freezes mid‑sentence
  81. Uses approved systems for work files