Knows theorganization’ssecuritypolicies existMentions“Thinkbeforeyou click”“If it seemstoo good tobe true, itprobably is”Recognizesa fake loginpage“Thislooks likea phishingattempt”CompletesannualsecuritytrainingShredsdocumentswithpersonal orclient infoNoticesspelling/grammarerrors in asuspicious emailUsescompany‑approvedcloud storageStoressensitivefilessecurelyFree!Recognizesa scam orfake offerKnowshow toreport anincidentLockscomputerwhensteppingawayKnows not toplugunknownUSBs intodevicesAvoidssharingcredentialswith anyoneReports asuspicioustextmessageUses securefile transferinstead ofemailattachmentAvoidssendingsensitive infounencryptedHoveringover linksbeforeclickingReports asuspiciousemailForwardsunusualemails to thesecurityteamAvoidsdownloadingunknownapplicationsIdentifiesa spoofedsendernameValidatespayment orchangerequeststhrough asecond channelDeclines toshareinformationover thephoneRecognizesan “urgent”or “act now”red flagRecognizesasuspiciousQR codeUses onlyapprovedtools forworkCreates astrongpassphrase(not just apassword)Double-checksexternalrecipientsbefore sendingIdentifiessuspiciousactivity ontheir accountUpdatessoftwarewhenpromptedDeletes datathey’re nolongerauthorized toretainUsesapprovedsystems forwork filesUsesmulti‑factorauthenticationAvoidspublicWi‑Fi forwork tasksDeletesunexpectedattachmentsVerifiessenderemailaddressAvoids takingphotos/screenshotsof client dataRecognizeswhensomeone asksfor too muchinformationKnows theorganization’ssecuritypolicies existMentions“Thinkbeforeyou click”“If it seemstoo good tobe true, itprobably is”Recognizesa fake loginpage“Thislooks likea phishingattempt”CompletesannualsecuritytrainingShredsdocumentswithpersonal orclient infoNoticesspelling/grammarerrors in asuspicious emailUsescompany‑approvedcloud storageStoressensitivefilessecurelyFree!Recognizesa scam orfake offerKnowshow toreport anincidentLockscomputerwhensteppingawayKnows not toplugunknownUSBs intodevicesAvoidssharingcredentialswith anyoneReports asuspicioustextmessageUses securefile transferinstead ofemailattachmentAvoidssendingsensitive infounencryptedHoveringover linksbeforeclickingReports asuspiciousemailForwardsunusualemails to thesecurityteamAvoidsdownloadingunknownapplicationsIdentifiesa spoofedsendernameValidatespayment orchangerequeststhrough asecond channelDeclines toshareinformationover thephoneRecognizesan “urgent”or “act now”red flagRecognizesasuspiciousQR codeUses onlyapprovedtools forworkCreates astrongpassphrase(not just apassword)Double-checksexternalrecipientsbefore sendingIdentifiessuspiciousactivity ontheir accountUpdatessoftwarewhenpromptedDeletes datathey’re nolongerauthorized toretainUsesapprovedsystems forwork filesUsesmulti‑factorauthenticationAvoidspublicWi‑Fi forwork tasksDeletesunexpectedattachmentsVerifiessenderemailaddressAvoids takingphotos/screenshotsof client dataRecognizeswhensomeone asksfor too muchinformation

General Security Awareness - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
  1. Knows the organization’s security policies exist
  2. Mentions “Think before you click”
  3. “If it seems too good to be true, it probably is”
  4. Recognizes a fake login page
  5. “This looks like a phishing attempt”
  6. Completes annual security training
  7. Shreds documents with personal or client info
  8. Notices spelling/grammar errors in a suspicious email
  9. Uses company‑approved cloud storage
  10. Stores sensitive files securely
  11. Free!
  12. Recognizes a scam or fake offer
  13. Knows how to report an incident
  14. Locks computer when stepping away
  15. Knows not to plug unknown USBs into devices
  16. Avoids sharing credentials with anyone
  17. Reports a suspicious text message
  18. Uses secure file transfer instead of email attachment
  19. Avoids sending sensitive info unencrypted
  20. Hovering over links before clicking
  21. Reports a suspicious email
  22. Forwards unusual emails to the security team
  23. Avoids downloading unknown applications
  24. Identifies a spoofed sender name
  25. Validates payment or change requests through a second channel
  26. Declines to share information over the phone
  27. Recognizes an “urgent” or “act now” red flag
  28. Recognizes a suspicious QR code
  29. Uses only approved tools for work
  30. Creates a strong passphrase (not just a password)
  31. Double-checks external recipients before sending
  32. Identifies suspicious activity on their account
  33. Updates software when prompted
  34. Deletes data they’re no longer authorized to retain
  35. Uses approved systems for work files
  36. Uses multi‑factor authentication
  37. Avoids public Wi‑Fi for work tasks
  38. Deletes unexpected attachments
  39. Verifies sender email address
  40. Avoids taking photos/screenshots of client data
  41. Recognizes when someone asks for too much information