Knowshow toreport anincident“If it seemstoo good tobe true, itprobably is”Usesapprovedsystems forwork filesReports asuspicioustextmessageStoressensitivefilessecurelyCompletesannualsecuritytrainingAvoids takingphotos/screenshotsof client dataAvoidsdownloadingunknownapplicationsAvoidssharingcredentialswith anyoneAvoidssendingsensitive infounencryptedDeclines toshareinformationover thephoneFree!Creates astrongpassphrase(not just apassword)Usescompany‑approvedcloud storageDeletes datathey’re nolongerauthorized toretainDeletesunexpectedattachmentsUses securefile transferinstead ofemailattachmentUses onlyapprovedtools forworkUsesmulti‑factorauthenticationRecognizeswhensomeone asksfor too muchinformationDouble-checksexternalrecipientsbefore sendingHoveringover linksbeforeclickingRecognizesa fake loginpageForwardsunusualemails to thesecurityteamIdentifiesa spoofedsendernameRecognizesan “urgent”or “act now”red flagRecognizesa scam orfake offerNoticesspelling/grammarerrors in asuspicious emailLockscomputerwhensteppingawayKnows theorganization’ssecuritypolicies existShredsdocumentswithpersonal orclient infoReports asuspiciousemailRecognizesasuspiciousQR codeUpdatessoftwarewhenpromptedAvoidspublicWi‑Fi forwork tasksValidatespayment orchangerequeststhrough asecond channel“Thislooks likea phishingattempt”Identifiessuspiciousactivity ontheir accountKnows not toplugunknownUSBs intodevicesMentions“Thinkbeforeyou click”VerifiessenderemailaddressKnowshow toreport anincident“If it seemstoo good tobe true, itprobably is”Usesapprovedsystems forwork filesReports asuspicioustextmessageStoressensitivefilessecurelyCompletesannualsecuritytrainingAvoids takingphotos/screenshotsof client dataAvoidsdownloadingunknownapplicationsAvoidssharingcredentialswith anyoneAvoidssendingsensitive infounencryptedDeclines toshareinformationover thephoneFree!Creates astrongpassphrase(not just apassword)Usescompany‑approvedcloud storageDeletes datathey’re nolongerauthorized toretainDeletesunexpectedattachmentsUses securefile transferinstead ofemailattachmentUses onlyapprovedtools forworkUsesmulti‑factorauthenticationRecognizeswhensomeone asksfor too muchinformationDouble-checksexternalrecipientsbefore sendingHoveringover linksbeforeclickingRecognizesa fake loginpageForwardsunusualemails to thesecurityteamIdentifiesa spoofedsendernameRecognizesan “urgent”or “act now”red flagRecognizesa scam orfake offerNoticesspelling/grammarerrors in asuspicious emailLockscomputerwhensteppingawayKnows theorganization’ssecuritypolicies existShredsdocumentswithpersonal orclient infoReports asuspiciousemailRecognizesasuspiciousQR codeUpdatessoftwarewhenpromptedAvoidspublicWi‑Fi forwork tasksValidatespayment orchangerequeststhrough asecond channel“Thislooks likea phishingattempt”Identifiessuspiciousactivity ontheir accountKnows not toplugunknownUSBs intodevicesMentions“Thinkbeforeyou click”Verifiessenderemailaddress

General Security Awareness - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
  1. Knows how to report an incident
  2. “If it seems too good to be true, it probably is”
  3. Uses approved systems for work files
  4. Reports a suspicious text message
  5. Stores sensitive files securely
  6. Completes annual security training
  7. Avoids taking photos/screenshots of client data
  8. Avoids downloading unknown applications
  9. Avoids sharing credentials with anyone
  10. Avoids sending sensitive info unencrypted
  11. Declines to share information over the phone
  12. Free!
  13. Creates a strong passphrase (not just a password)
  14. Uses company‑approved cloud storage
  15. Deletes data they’re no longer authorized to retain
  16. Deletes unexpected attachments
  17. Uses secure file transfer instead of email attachment
  18. Uses only approved tools for work
  19. Uses multi‑factor authentication
  20. Recognizes when someone asks for too much information
  21. Double-checks external recipients before sending
  22. Hovering over links before clicking
  23. Recognizes a fake login page
  24. Forwards unusual emails to the security team
  25. Identifies a spoofed sender name
  26. Recognizes an “urgent” or “act now” red flag
  27. Recognizes a scam or fake offer
  28. Notices spelling/grammar errors in a suspicious email
  29. Locks computer when stepping away
  30. Knows the organization’s security policies exist
  31. Shreds documents with personal or client info
  32. Reports a suspicious email
  33. Recognizes a suspicious QR code
  34. Updates software when prompted
  35. Avoids public Wi‑Fi for work tasks
  36. Validates payment or change requests through a second channel
  37. “This looks like a phishing attempt”
  38. Identifies suspicious activity on their account
  39. Knows not to plug unknown USBs into devices
  40. Mentions “Think before you click”
  41. Verifies sender email address