Recognizesan “urgent”or “act now”red flagKnowshow toreport anincidentUses securefile transferinstead ofemailattachmentMentions“Thinkbeforeyou click”StoressensitivefilessecurelyValidatespayment orchangerequeststhrough asecond channelUses onlyapprovedtools forworkShredsdocumentswithpersonal orclient infoRecognizesa scam orfake offerDeclines toshareinformationover thephoneReports asuspicioustextmessageIdentifiesa spoofedsendername“If it seemstoo good tobe true, itprobably is”Recognizeswhensomeone asksfor too muchinformationFree!Recognizesa fake loginpageUsesmulti‑factorauthenticationRecognizesasuspiciousQR codeAvoids takingphotos/screenshotsof client dataHoveringover linksbeforeclickingVerifiessenderemailaddressDouble-checksexternalrecipientsbefore sendingUsescompany‑approvedcloud storageAvoidsdownloadingunknownapplicationsDeletesunexpectedattachmentsForwardsunusualemails to thesecurityteamKnows not toplugunknownUSBs intodevicesNoticesspelling/grammarerrors in asuspicious emailCompletesannualsecuritytrainingAvoidssharingcredentialswith anyoneUsesapprovedsystems forwork filesLockscomputerwhensteppingawayAvoidssendingsensitive infounencryptedReports asuspiciousemailIdentifiessuspiciousactivity ontheir accountCreates astrongpassphrase(not just apassword)Deletes datathey’re nolongerauthorized toretainUpdatessoftwarewhenprompted“Thislooks likea phishingattempt”Knows theorganization’ssecuritypolicies existAvoidspublicWi‑Fi forwork tasksRecognizesan “urgent”or “act now”red flagKnowshow toreport anincidentUses securefile transferinstead ofemailattachmentMentions“Thinkbeforeyou click”StoressensitivefilessecurelyValidatespayment orchangerequeststhrough asecond channelUses onlyapprovedtools forworkShredsdocumentswithpersonal orclient infoRecognizesa scam orfake offerDeclines toshareinformationover thephoneReports asuspicioustextmessageIdentifiesa spoofedsendername“If it seemstoo good tobe true, itprobably is”Recognizeswhensomeone asksfor too muchinformationFree!Recognizesa fake loginpageUsesmulti‑factorauthenticationRecognizesasuspiciousQR codeAvoids takingphotos/screenshotsof client dataHoveringover linksbeforeclickingVerifiessenderemailaddressDouble-checksexternalrecipientsbefore sendingUsescompany‑approvedcloud storageAvoidsdownloadingunknownapplicationsDeletesunexpectedattachmentsForwardsunusualemails to thesecurityteamKnows not toplugunknownUSBs intodevicesNoticesspelling/grammarerrors in asuspicious emailCompletesannualsecuritytrainingAvoidssharingcredentialswith anyoneUsesapprovedsystems forwork filesLockscomputerwhensteppingawayAvoidssendingsensitive infounencryptedReports asuspiciousemailIdentifiessuspiciousactivity ontheir accountCreates astrongpassphrase(not just apassword)Deletes datathey’re nolongerauthorized toretainUpdatessoftwarewhenprompted“Thislooks likea phishingattempt”Knows theorganization’ssecuritypolicies existAvoidspublicWi‑Fi forwork tasks

General Security Awareness - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
  1. Recognizes an “urgent” or “act now” red flag
  2. Knows how to report an incident
  3. Uses secure file transfer instead of email attachment
  4. Mentions “Think before you click”
  5. Stores sensitive files securely
  6. Validates payment or change requests through a second channel
  7. Uses only approved tools for work
  8. Shreds documents with personal or client info
  9. Recognizes a scam or fake offer
  10. Declines to share information over the phone
  11. Reports a suspicious text message
  12. Identifies a spoofed sender name
  13. “If it seems too good to be true, it probably is”
  14. Recognizes when someone asks for too much information
  15. Free!
  16. Recognizes a fake login page
  17. Uses multi‑factor authentication
  18. Recognizes a suspicious QR code
  19. Avoids taking photos/screenshots of client data
  20. Hovering over links before clicking
  21. Verifies sender email address
  22. Double-checks external recipients before sending
  23. Uses company‑approved cloud storage
  24. Avoids downloading unknown applications
  25. Deletes unexpected attachments
  26. Forwards unusual emails to the security team
  27. Knows not to plug unknown USBs into devices
  28. Notices spelling/grammar errors in a suspicious email
  29. Completes annual security training
  30. Avoids sharing credentials with anyone
  31. Uses approved systems for work files
  32. Locks computer when stepping away
  33. Avoids sending sensitive info unencrypted
  34. Reports a suspicious email
  35. Identifies suspicious activity on their account
  36. Creates a strong passphrase (not just a password)
  37. Deletes data they’re no longer authorized to retain
  38. Updates software when prompted
  39. “This looks like a phishing attempt”
  40. Knows the organization’s security policies exist
  41. Avoids public Wi‑Fi for work tasks