Teamviewer/ VNCShares with"Everyone,Full Control"Usersare localadminsNoEDRNo IRPlan"We justuseWindowsDefender"Individualpermissionsin sharesNo driveencryptionTelnetUnidentifiedPCIrequirementsWindows7Plain textpassworddiscoveredin shareAdobeFlashNoSPFrecordcrackedadminpasswordMinimalGroupPolicyPasswordsneverexpireDNSloggingnotenabledNo DRPlanpasswordspreadsheetStaleObjectsolder than1yearWindowsXPInappropriteFirewallrules (notRDP)"We'venever hadanincident."WindowsServer2003/2008NooffsitebackupsWhitelisteddomains inemail filterclosetspaghettiManualBackupsNoMFA"We updatewhen thereareproblems"WirelessPSK olderthan 2yearsUnlicensedhardwareor softwareNo truenetworksegmentationComputersnot joinedto DomainGuestSSID butnoisolation>50%passwordscrackedNoSecurityAwarenessTrainingUnpatchedExchangeDefaultadmincredentialsDefaultSNMPWritevalueNoDMZNoDKIM /DMARCExternalRDP"We're assecure aswe canbe."Teamviewer/ VNCShares with"Everyone,Full Control"Usersare localadminsNoEDRNo IRPlan"We justuseWindowsDefender"Individualpermissionsin sharesNo driveencryptionTelnetUnidentifiedPCIrequirementsWindows7Plain textpassworddiscoveredin shareAdobeFlashNoSPFrecordcrackedadminpasswordMinimalGroupPolicyPasswordsneverexpireDNSloggingnotenabledNo DRPlanpasswordspreadsheetStaleObjectsolder than1yearWindowsXPInappropriteFirewallrules (notRDP)"We'venever hadanincident."WindowsServer2003/2008NooffsitebackupsWhitelisteddomains inemail filterclosetspaghettiManualBackupsNoMFA"We updatewhen thereareproblems"WirelessPSK olderthan 2yearsUnlicensedhardwareor softwareNo truenetworksegmentationComputersnot joinedto DomainGuestSSID butnoisolation>50%passwordscrackedNoSecurityAwarenessTrainingUnpatchedExchangeDefaultadmincredentialsDefaultSNMPWritevalueNoDMZNoDKIM /DMARCExternalRDP"We're assecure aswe canbe."

Risk Assessment Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
  1. Teamviewer / VNC
  2. Shares with "Everyone, Full Control"
  3. Users are local admins
  4. No EDR
  5. No IR Plan
  6. "We just use Windows Defender"
  7. Individual permissions in shares
  8. No drive encryption
  9. Telnet
  10. Unidentified PCI requirements
  11. Windows 7
  12. Plain text password discovered in share
  13. Adobe Flash
  14. No SPF record
  15. cracked admin password
  16. Minimal Group Policy
  17. Passwords never expire
  18. DNS logging not enabled
  19. No DR Plan
  20. password spreadsheet
  21. Stale Objects older than 1year
  22. Windows XP
  23. Inapproprite Firewall rules (not RDP)
  24. "We've never had an incident."
  25. Windows Server 2003/2008
  26. No offsite backups
  27. Whitelisted domains in email filter
  28. closet spaghetti
  29. Manual Backups
  30. No MFA
  31. "We update when there are problems"
  32. Wireless PSK older than 2 years
  33. Unlicensed hardware or software
  34. No true network segmentation
  35. Computers not joined to Domain
  36. Guest SSID but no isolation
  37. >50% passwords cracked
  38. No Security Awareness Training
  39. Unpatched Exchange
  40. Default admin credentials
  41. Default SNMP Write value
  42. No DMZ
  43. No DKIM / DMARC
  44. External RDP
  45. "We're as secure as we can be."