Recognizesan “urgent”or “act now”red flagCreates astrongpassphrase(not just apassword)“Can yousee myscreen?”“You’reonmute.”Using securefile transferinstead ofemailDeclines toshareinformationover thephoneAvoidssharingcredentialswith anyoneSuspiciouslogin alertAttending asecurityawarenesstrainingsessionUsescompany‑approvedcloud storageReportinga lost orstolendeviceHoveringover linksbeforeclickingStrongpassphraseused (notjust complexpassword)Excessivepermissions(over‑privilegedaccess)“We’ll acceptthe risk”(withoutdocumentation😉)Saying “If itseems toogood to betrue, itprobably is”Validatespayment orchangerequeststhrough asecond channelDeletes datathey’re nolongerauthorized toretainRecognizesasuspiciousQR codeKnows not toplugunknownUSBs intodevicesReports asuspicioustextmessageRecognizeswhensomeone asksfor too muchinformationUsesapprovedsystems forwork filesVerifiessenderemailaddressUSB stickplugged intoa corporatelaptopLockscomputerwhensteppingawayComputerscreenlockedwhen awayDouble-checking anexternalemailrecipientSharedcredentialsdiscoveredPublic linksharingdisabledon a fileDefaultpasswordstill in useDouble-checksexternalrecipientsbefore sendingAvoidssendingsensitive infounencryptedShredsdocumentswithpersonal orclient infoUnpatchedsystemidentified“Thislooks likea phishingattempt”High-riskvendorflaggedData notclassifiedcorrectlySomeonementions“Zerotrust.”Missingevidencefor anaudit testAvoids takingphotos/screenshotsof client dataStoressensitivefilessecurelyUses securefile transferinstead ofemailattachmentMissing BAAfor aPHI‑handlingvendorSlide witha lot oftiny textNodocumentedincidentresponseplanSomeonementions“AI” or“Copilot.”Free!Identifiessuspiciousactivity ontheir accountSomeone’sconnectionfreezesmid‑sentenceNoticesspelling/grammarerrors in asuspicious emailVerifying apayment/changerequest viaphoneQuarterlyaccessreviewcompletedUses onlyapprovedtools forworkPetappearsoncameraVendorwithoutrecent SOC2 reportReports asuspiciousemailUpdatessoftwarewhenpromptedRecognizesa scam orfake offerCompletesannualsecuritytrainingAvoidsdownloadingunknownapplicationsSomeonesays “Let’stake thatoffline.”DeletesunexpectedattachmentsMentions“Thinkbeforeyou click”“Sorry, Iwas onanothercall.”Recognizesa fake loginpageSomeonesays, “That’sa greatquestion.”Knows theorganization’ssecuritypolicies existPhishingemailreportedUpdatingsoftwarewhenpromptedForwardsunusualemails to thesecurityteamSensitivedata sent viaunencryptedemailAvoidspublicWi‑Fi forwork tasksMulti-factorauthentication(MFA)enabledFirewallrule allows“ANY/ANY”trafficEmployeeuses the“ReportPhish”buttonUsesmulti‑factorauthentication“If it seemstoo good tobe true, itprobably is”“ShadowIT” appfoundKnowshow toreport anincidentIdentifiesa spoofedsendernameRecognizesan “urgent”or “act now”red flagCreates astrongpassphrase(not just apassword)“Can yousee myscreen?”“You’reonmute.”Using securefile transferinstead ofemailDeclines toshareinformationover thephoneAvoidssharingcredentialswith anyoneSuspiciouslogin alertAttending asecurityawarenesstrainingsessionUsescompany‑approvedcloud storageReportinga lost orstolendeviceHoveringover linksbeforeclickingStrongpassphraseused (notjust complexpassword)Excessivepermissions(over‑privilegedaccess)“We’ll acceptthe risk”(withoutdocumentation😉)Saying “If itseems toogood to betrue, itprobably is”Validatespayment orchangerequeststhrough asecond channelDeletes datathey’re nolongerauthorized toretainRecognizesasuspiciousQR codeKnows not toplugunknownUSBs intodevicesReports asuspicioustextmessageRecognizeswhensomeone asksfor too muchinformationUsesapprovedsystems forwork filesVerifiessenderemailaddressUSB stickplugged intoa corporatelaptopLockscomputerwhensteppingawayComputerscreenlockedwhen awayDouble-checking anexternalemailrecipientSharedcredentialsdiscoveredPublic linksharingdisabledon a fileDefaultpasswordstill in useDouble-checksexternalrecipientsbefore sendingAvoidssendingsensitive infounencryptedShredsdocumentswithpersonal orclient infoUnpatchedsystemidentified“Thislooks likea phishingattempt”High-riskvendorflaggedData notclassifiedcorrectlySomeonementions“Zerotrust.”Missingevidencefor anaudit testAvoids takingphotos/screenshotsof client dataStoressensitivefilessecurelyUses securefile transferinstead ofemailattachmentMissing BAAfor aPHI‑handlingvendorSlide witha lot oftiny textNodocumentedincidentresponseplanSomeonementions“AI” or“Copilot.”Free!Identifiessuspiciousactivity ontheir accountSomeone’sconnectionfreezesmid‑sentenceNoticesspelling/grammarerrors in asuspicious emailVerifying apayment/changerequest viaphoneQuarterlyaccessreviewcompletedUses onlyapprovedtools forworkPetappearsoncameraVendorwithoutrecent SOC2 reportReports asuspiciousemailUpdatessoftwarewhenpromptedRecognizesa scam orfake offerCompletesannualsecuritytrainingAvoidsdownloadingunknownapplicationsSomeonesays “Let’stake thatoffline.”DeletesunexpectedattachmentsMentions“Thinkbeforeyou click”“Sorry, Iwas onanothercall.”Recognizesa fake loginpageSomeonesays, “That’sa greatquestion.”Knows theorganization’ssecuritypolicies existPhishingemailreportedUpdatingsoftwarewhenpromptedForwardsunusualemails to thesecurityteamSensitivedata sent viaunencryptedemailAvoidspublicWi‑Fi forwork tasksMulti-factorauthentication(MFA)enabledFirewallrule allows“ANY/ANY”trafficEmployeeuses the“ReportPhish”buttonUsesmulti‑factorauthentication“If it seemstoo good tobe true, itprobably is”“ShadowIT” appfoundKnowshow toreport anincidentIdentifiesa spoofedsendername

General Security Awareness - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
  1. Recognizes an “urgent” or “act now” red flag
  2. Creates a strong passphrase (not just a password)
  3. “Can you see my screen?”
  4. “You’re on mute.”
  5. Using secure file transfer instead of email
  6. Declines to share information over the phone
  7. Avoids sharing credentials with anyone
  8. Suspicious login alert
  9. Attending a security awareness training session
  10. Uses company‑approved cloud storage
  11. Reporting a lost or stolen device
  12. Hovering over links before clicking
  13. Strong passphrase used (not just complex password)
  14. Excessive permissions (over‑privileged access)
  15. “We’ll accept the risk” (without documentation 😉)
  16. Saying “If it seems too good to be true, it probably is”
  17. Validates payment or change requests through a second channel
  18. Deletes data they’re no longer authorized to retain
  19. Recognizes a suspicious QR code
  20. Knows not to plug unknown USBs into devices
  21. Reports a suspicious text message
  22. Recognizes when someone asks for too much information
  23. Uses approved systems for work files
  24. Verifies sender email address
  25. USB stick plugged into a corporate laptop
  26. Locks computer when stepping away
  27. Computer screen locked when away
  28. Double-checking an external email recipient
  29. Shared credentials discovered
  30. Public link sharing disabled on a file
  31. Default password still in use
  32. Double-checks external recipients before sending
  33. Avoids sending sensitive info unencrypted
  34. Shreds documents with personal or client info
  35. Unpatched system identified
  36. “This looks like a phishing attempt”
  37. High-risk vendor flagged
  38. Data not classified correctly
  39. Someone mentions “Zero trust.”
  40. Missing evidence for an audit test
  41. Avoids taking photos/screenshots of client data
  42. Stores sensitive files securely
  43. Uses secure file transfer instead of email attachment
  44. Missing BAA for a PHI‑handling vendor
  45. Slide with a lot of tiny text
  46. No documented incident response plan
  47. Someone mentions “AI” or “Copilot.”
  48. Free!
  49. Identifies suspicious activity on their account
  50. Someone’s connection freezes mid‑sentence
  51. Notices spelling/grammar errors in a suspicious email
  52. Verifying a payment/change request via phone
  53. Quarterly access review completed
  54. Uses only approved tools for work
  55. Pet appears on camera
  56. Vendor without recent SOC 2 report
  57. Reports a suspicious email
  58. Updates software when prompted
  59. Recognizes a scam or fake offer
  60. Completes annual security training
  61. Avoids downloading unknown applications
  62. Someone says “Let’s take that offline.”
  63. Deletes unexpected attachments
  64. Mentions “Think before you click”
  65. “Sorry, I was on another call.”
  66. Recognizes a fake login page
  67. Someone says, “That’s a great question.”
  68. Knows the organization’s security policies exist
  69. Phishing email reported
  70. Updating software when prompted
  71. Forwards unusual emails to the security team
  72. Sensitive data sent via unencrypted email
  73. Avoids public Wi‑Fi for work tasks
  74. Multi-factor authentication (MFA) enabled
  75. Firewall rule allows “ANY/ANY” traffic
  76. Employee uses the “Report Phish” button
  77. Uses multi‑factor authentication
  78. “If it seems too good to be true, it probably is”
  79. “Shadow IT” app found
  80. Knows how to report an incident
  81. Identifies a spoofed sender name